Junglewise Threat Intelligence

CVE-2026-20915: Checkmk stored XSS in Pending Changes sidebar

CVE-2026-20915 · Severity: medium · CVSS 5.4 · Published 2026-03-31

Technologies: Checkmk. Vendors: Checkmk.

Executive brief

Checkmk, a popular IT infrastructure monitoring platform, contains a security flaw that allows certain authorized users to inject malicious scripts into the management interface. If an administrator or another user views the 'Pending Changes' sidebar, these scripts could execute in their browser, potentially leading to unauthorized actions or data theft. This issue affects organizations using the 2.5.0 beta version of the software.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Checkmk version 2.5.0 (beta) before 2.5.0b2. The 'Pending Changes' sidebar fails to properly sanitize change attributes before rendering them in the web interface. An authenticated attacker with permissions to create pending changes can inject arbitrary JavaScript into these attributes. When other users (such as administrators) view the sidebar, the malicious payload executes in their security context. This can lead to session hijacking or unauthorized configuration changes. The issue is resolved in version 2.5.0b2.

Affected products

  • Checkmk GmbH Checkmk 2.5.0 (beta) before 2.5.0b2

Timeline

  • 2026-03-23: patched: Vendor released fix in version 2.5.0b2
  • 2026-03-31: disclosed: CVE published and vendor advisory released

References

Related threats