CVE Database
/

CVE-2026-33456

Back to search

CVE-2026-33456

Published: Apr 10, 2026

Modified: Apr 14, 2026

PUBLISHED

Description

Livestatus injection in the notification test mode in Checkmk <2.5.0b4 and <2.4.0p26 allows an authenticated user with access to the notification test page to inject arbitrary Livestatus commands via a crafted service description.

VendorProductVersions

Checkmk GmbH

Checkmk

affected
2.5.0 - < 2.5.0b4
affected
2.4.0 - < 2.4.0p26

Weaknesses (CWE)

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now