CRITICAL🇵🇱 Wersja polska

CVE-2025-39666

CVSS 9.3v4.0pub. 2026-04-07upd. 2026-04-14

Local privilege escalation in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0b3 allows a site user to escalate their privileges to root, by manipulating files in the site context that are processed when the `omd` administrative command is run by root.

🤖 AI Analysis
How it works

The vulnerability results from improper path resolution (CWE-426 — Untrusted Search Path) and inclusion of files from untrusted locations (CWE-829 — Inclusion of Functionality from Untrusted Control Sphere). A user with access to the Checkmk site context can manipulate files that are processed during execution of the administrative `omd` command running with root privileges. By substituting or modifying these files, the attacker can achieve arbitrary code execution in the context of the process running as root.

Impact

An attacker with local access to the Checkmk site can obtain full root privileges on the server, enabling complete system takeover, configuration modification, data theft, and persistent access maintenance.

Mitigation & patch

Checkmk must be updated to version 2.3.0p46 or later (for 2.3.0 branch), 2.4.0p25 or later (for 2.4.0 branch), or 2.5.0b3 or later (for 2.5.0 beta version). Version 2.2.0 has reached EOL status and will not receive a patch — migration to a supported version is required. Details available at: https://checkmk.com/werk/18891

Who is affected

Checkmk 2.2.0 (EOL version), Checkmk 2.3.0 before version 2.3.0p46, Checkmk 2.4.0 before version 2.4.0p25, Checkmk 2.5.0 (beta) before version 2.5.0b3

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Checkmk

    APP
    Checkmk
    2.2.02.3.02.4.02.5.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
References

Related vulnerabilities

CVE-2024-8606CRITICAL9.2PL ✓same product

Pominięcie uwierzytelnienia dwuskładnikowego (2FA) w Checkmk RestAPI

CVE-2022-46836CRITICAL9.1PL ✓same product

PHP code injection w Checkmk — wstrzyknięcie i wykonanie kodu PHP (RCE)

CVE-2026-7186HIGH8.5same product

Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2...

CVE-2026-8833HIGH8.5same product

Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p...

CVE-2026-3466HIGH8.5same product

Insufficient sanitization of dashboard dashlet title links in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p...