Command Injection Vulnerability in Checkmk by Tribe29
CVE-2026-33455

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
10 April 2026

What is CVE-2026-33455?

A command injection vulnerability exists in Checkmk's monitoring quicksearch feature, allowing authenticated attackers to execute livestatus commands through manipulated search queries. This stems from inadequate input validation within the search filter plugins, which can lead to unauthorized command execution and potentially compromise system integrity.

Affected Version(s)

Checkmk 2.5.0 < 2.5.0b4

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.