PT-2026-58000 · Checkmk Gmbh+1 · Checkmk

CVE-2026-14852

·

Published

2026-07-14

·

Updated

2026-07-14

CVSS v4.0

5.2

Medium

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Checkmk versions 2.5.0 through 2.5.0p8 Checkmk versions 2.4.0 through 2.4.0p33 Checkmk versions 2.3.0 through 2.3.0p48 Checkmk version 2.2.0
Description A privilege escalation issue exists where a local unprivileged user can execute arbitrary commands as root. This occurs when the mk sap hana agent plugin runs as root with RUNAS=agent and lacks an explicit database configuration. In this state, the plugin derives instance identifiers from the process list to build a command executed with elevated privileges, which can be exploited by starting a process crafted to mimic a SAP HANA instance.
Recommendations Update Checkmk versions 2.5.0 through 2.5.0p8 to version 2.5.0p9. Update Checkmk versions 2.4.0 through 2.4.0p33 to version 2.4.0p34. Update Checkmk versions 2.3.0 through 2.3.0p48 to version 2.3.0p49. At the moment, there is no information about a newer version that contains a fix for this vulnerability for version 2.2.0.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14852

Affected Products

Checkmk