CVE 4.8 MEDIUM

Fix XSS in service discovery active check output_CVE-2026-9549

4.8 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N

Description

Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can configure active or custom checks to inject malicious HTML or JavaScript into check output that executes in the browser of an admin or a user with host read permissions when they run the check on the service discovery page.

Basic Information

ID CVE-2026-9549
Source Checkmk
Published Jun 8, 2026 at 12:07

Affected Product

Vendor Checkmk GmbH
Product Checkmk
Version 2.5.0
Affected Versions Checkmk GmbH Checkmk 2.5.0
Checkmk GmbH Checkmk 2.4.0
Checkmk GmbH Checkmk 2.3.0
Checkmk GmbH Checkmk 2.2.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.