Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can configure active or custom checks to inject malicious HTML or JavaScript into check output that executes in the browser of an admin or a user with host read permissions when they run the check on the service discovery page.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://checkmk.com/werk/17993 |
|
History
Mon, 08 Jun 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can configure active or custom checks to inject malicious HTML or JavaScript into check output that executes in the browser of an admin or a user with host read permissions when they run the check on the service discovery page. | |
| Title | Fix XSS in service discovery active check output | |
| First Time appeared |
Checkmk
Checkmk checkmk |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Checkmk
Checkmk checkmk |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Checkmk
Published:
Updated: 2026-06-08T13:02:20.748Z
Reserved: 2026-05-26T07:04:28.900Z
Link: CVE-2026-9549
No data.
Status : Received
Published: 2026-06-08T13:16:34.030
Modified: 2026-06-08T13:16:34.030
Link: CVE-2026-9549
No data.
OpenCVE Enrichment
No data.