PT-2026-47284 · Checkmk · Checkmk

CVE-2026-7186

·

Published

2026-06-08

·

Updated

2026-06-08

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Checkmk versions prior to 2.5.0p5 Checkmk versions prior to 2.4.0p31 Checkmk versions prior to 2.3.0p48 Checkmk version 2.2.0
Description Stored cross-site scripting occurs in the URL dashboard widget. A user with dashboard editing permissions can store a URL using a dangerous URI scheme, such as javascript:, which executes scripts in the browsers of other users who view the dashboard.
Recommendations Update to version 2.5.0p5 or later. Update to version 2.4.0p31 or later. Update to version 2.3.0p48 or later. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7186

Affected Products

Checkmk