CVE Database
/

CVE-2025-64998

Back to search

CVE-2025-64998

Published: Mar 24, 2026

Modified: Mar 25, 2026

PUBLISHED

Description

Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site with config sync enabled to hijack sessions on the central site by forging session cookies.

VendorProductVersions

Checkmk GmbH

Checkmk

affected
2.4.0 - < 2.4.0p23
affected
2.3.0 - < 2.3.0p45
affected
2.2.0

Weaknesses (CWE)

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now