Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allows an authenticated user to inject arbitrary Livestatus commands via a crafted service name parameter due to insufficient sanitization of the service description value.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://checkmk.com/werk/17990 |
|
History
Fri, 10 Apr 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allows an authenticated user to inject arbitrary Livestatus commands via a crafted service name parameter due to insufficient sanitization of the service description value. | |
| Title | Potential livestatus injection in prediction graph page | |
| First Time appeared |
Checkmk
Checkmk checkmk |
|
| Weaknesses | CWE-140 | |
| CPEs | cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Checkmk
Checkmk checkmk |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Checkmk
Published:
Updated: 2026-04-10T08:31:35.768Z
Reserved: 2026-03-20T10:30:13.353Z
Link: CVE-2026-33457
No data.
Status : Received
Published: 2026-04-10T09:16:24.630
Modified: 2026-04-10T09:16:24.630
Link: CVE-2026-33457
No data.
OpenCVE Enrichment
No data.
Weaknesses