Executive brief
A security vulnerability in the Checkmk monitoring agent could allow a local user to gain full administrative control over a Linux server. By creating a specially named process that mimics a SAP HANA database, an attacker can trick the monitoring software into executing unauthorized commands with root privileges. This issue affects organizations using Checkmk to monitor SAP HANA environments where the monitoring plugin is configured to run with elevated permissions.
Technical details
An OS command injection vulnerability (CWE-78) exists in the mk_sap_hana agent plugin of Checkmk. When no explicit database configuration is provided, the plugin automatically discovers SAP HANA instances by scanning the system process list for 'sapstartsrv'. Because local users can control their own process names, an attacker can craft a process name containing malicious shell commands. If the plugin is configured to run as root (typically via RUNAS=agent), it extracts the instance identifier from the spoofed process name and incorporates it into a command string executed with elevated privileges. The fix implements strict validation to ensure instance identifiers match the expected format of genuine SAP HANA instances.
Affected products
- Checkmk GmbH Checkmk 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, 2.2.0 (EOL)
Timeline
- 2026-07-07: advisory: Vendor advisory Werk #20104 published
- 2026-07-14: disclosed: CVE published to NVD