Command Injection Vulnerability in Checkmk by Tribe29
CVE-2026-33455
5.3MEDIUM
What is CVE-2026-33455?
A command injection vulnerability exists in Checkmk's monitoring quicksearch feature, allowing authenticated attackers to execute livestatus commands through manipulated search queries. This stems from inadequate input validation within the search filter plugins, which can lead to unauthorized command execution and potentially compromise system integrity.
Affected Version(s)
Checkmk 2.5.0 < 2.5.0b4
