8.5
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:L/SA:N
Description
Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an authenticated user to bypass URL validation and inject malicious URLs such as javascript: URIs, resulting in cross-site scripting when another user interacts with the crafted link.
AI Analysis
Cross-site scripting vulnerability due to improper neutralization of HTML-encoded characters in the URL validation function
Basic Information
ID
CVE-2026-8833
Source
Checkmk
Published
Jun 8, 2026 at 12:06
Affected Product
Vendor
Checkmk GmbH
Product
Checkmk
Version
2.5.0
Affected Versions
Checkmk GmbH Checkmk 2.5.0
Checkmk GmbH Checkmk 2.4.0
Checkmk GmbH Checkmk 2.3.0
Checkmk GmbH Checkmk 2.2.0
Checkmk GmbH Checkmk 2.4.0
Checkmk GmbH Checkmk 2.3.0
Checkmk GmbH Checkmk 2.2.0
CWE Classification
AI Assessment
AI Score
8.5 / 10
AI Severity
High
Vendor
Checkmk GmbH
Product
Checkmk
Version
2.5.0, 2.4.0, 2.3.0, 2.2.0