CVE 8.5 HIGH

XSS in urls_CVE-2026-8833

8.5 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:L/SA:N

Description

Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an authenticated user to bypass URL validation and inject malicious URLs such as javascript: URIs, resulting in cross-site scripting when another user interacts with the crafted link.

AI Analysis

Cross-site scripting vulnerability due to improper neutralization of HTML-encoded characters in the URL validation function

Basic Information

ID CVE-2026-8833
Source Checkmk
Published Jun 8, 2026 at 12:06

Affected Product

Vendor Checkmk GmbH
Product Checkmk
Version 2.5.0
Affected Versions Checkmk GmbH Checkmk 2.5.0
Checkmk GmbH Checkmk 2.4.0
Checkmk GmbH Checkmk 2.3.0
Checkmk GmbH Checkmk 2.2.0

CWE Classification

AI Assessment

AI Score 8.5 / 10
AI Severity High
Vendor Checkmk GmbH
Product Checkmk
Version 2.5.0, 2.4.0, 2.3.0, 2.2.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.