CVE detail
CVE-2025-39666 — CVE-2025-39666
Published 2026-04-07 · Modified 2026-06-17 · Vendor checkmk · Product checkmk · Source nvd
HIGH
severity
CVSS-derived band
0.0012
EPSS probability
exploitation probability, 30d
2.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Local privilege escalation in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0b3 allows a site user to escalate their privileges to root, by manipulating files in the site context that are processed when the `omd` administrative command is run by root.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References