cvedb.io
CVE-2026-9549
MEDIUM · CVSS 4.8
EPSS exploitation probability: 0%
Published 2026-06-08T13:16:34.030 · Last modified 2026-06-17T11:05:28.357

Summary

Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can configure active or custom checks to inject malicious HTML or JavaScript into check output that executes in the browser of an admin or a user with host read permissions when they run the check on the service discovery page.

Affected products

checkmk — checkmk

Does this affect you?

Add your gear to cvedb and we'll alert you only when checkmk ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.