Livestatus Injection Vulnerability in Checkmk by Tribe29
CVE-2026-33457
5.3MEDIUM
What is CVE-2026-33457?
The Checkmk product from Tribe29 has a vulnerability that allows authenticated users to inject arbitrary Livestatus commands via a crafted service name parameter on the prediction graph page. This occurs due to a failure to properly sanitize the service description value, thereby opening a potential attack vector for user exploitation.
Affected Version(s)
Checkmk 2.5.0 < 2.5.0b4
Checkmk 2.4.0 < 2.4.0p26
Checkmk 2.3.0 < 2.3.0p47
