PT-2026-47287 · Checkmk · Checkmk

CVE-2026-8833

·

Published

2026-06-08

·

Updated

2026-06-08

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Checkmk versions prior to 2.5.0p5 Checkmk versions prior to 2.4.0p31 Checkmk versions prior to 2.3.0p48 Checkmk versions 2.2.0
Description Improper neutralization of HTML-encoded characters in the URL validation function allows an authenticated user to bypass validation and inject malicious URLs, such as javascript: URIs. This leads to cross-site scripting (XSS), a technique where malicious scripts are injected into trusted websites, when another user interacts with the crafted link.
Recommendations Update to version 2.5.0p5 or later. Update to version 2.4.0p31 or later. Update to version 2.3.0p48 or later. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8833

Affected Products

Checkmk