Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://checkmk.com/werk/17988 |
|
Mon, 20 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:checkmk:checkmk:2.5.0:b1:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.5.0:b2:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.5.0:b3:*:*:*:*:*:* |
|
| Metrics |
cvssV3_1
|
Tue, 14 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Fri, 10 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Apr 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Livestatus injection in the monitoring quicksearch in Checkmk <2.5.0b4 allows an authenticated attacker to inject livestatus commands via the search query due to insufficient input sanitization in search filter plugins. | |
| Title | Livestatus injection in monitoring quicksearch | |
| First Time appeared |
Checkmk
Checkmk checkmk |
|
| Weaknesses | CWE-140 | |
| CPEs | cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Checkmk
Checkmk checkmk |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Checkmk
Published:
Updated: 2026-04-14T13:30:16.535Z
Reserved: 2026-03-20T10:30:13.352Z
Link: CVE-2026-33455
Updated: 2026-04-10T12:48:23.351Z
Status : Analyzed
Published: 2026-04-10T09:16:23.447
Modified: 2026-04-20T17:10:27.397
Link: CVE-2026-33455
No data.
OpenCVE Enrichment
Updated: 2026-04-10T14:40:54Z