Improper Input Handling in Checkmk Web Monitoring Tool
CVE-2026-90990

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-90990?

In Checkmk versions prior to 2.5.0p14, a vulnerability was identified that allows authenticated users to improperly manipulate filter values in the monitoring host and service list APIs. This flaw enables attackers to inject additional Livestatus query headers, effectively circumventing object visibility restrictions. Consequently, attackers can glean information about hosts and services that are outside their designated contact groups, ultimately affecting the performance of web servers and Livestatus workers as they handle these unauthorized queries.

Affected Version(s)

Checkmk 2.5.0 < 2.5.0p14

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.