Local Privilege Escalation Vulnerability in Checkmk by Tribe29
CVE-2026-105331

5.2MEDIUM

Key Information:

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-105331?

An elevation of privilege issue exists in Checkmk versions prior to 2.5.0p10. Specifically, users with the ability to edit the Oracle Instant Client through the 'mk-oracle' agent plugin can exploit this vulnerability to gain elevated privileges. If the agent has this plugin enabled, it could allow unauthorized users to escalate their privileges, leading to potential unauthorized access and manipulation of critical system resources.

Affected Version(s)

Checkmk 2.5.0 < 2.5.0p10

References

CVSS V4

Score:
5.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.