Improper Input Handling in Checkmk Web Monitoring Tool
CVE-2026-90990
5.3MEDIUM
What is CVE-2026-90990?
In Checkmk versions prior to 2.5.0p14, a vulnerability was identified that allows authenticated users to improperly manipulate filter values in the monitoring host and service list APIs. This flaw enables attackers to inject additional Livestatus query headers, effectively circumventing object visibility restrictions. Consequently, attackers can glean information about hosts and services that are outside their designated contact groups, ultimately affecting the performance of web servers and Livestatus workers as they handle these unauthorized queries.
Affected Version(s)
Checkmk 2.5.0 < 2.5.0p14
