Junglewise Threat Intelligence

CVE-2026-33457: Checkmk Livestatus injection in prediction graph page

CVE-2026-33457 · Severity: medium · CVSS 6.3 · Published 2026-04-10

Technologies: Checkmk. Vendors: Checkmk.

Executive brief

Checkmk is an IT infrastructure monitoring platform used to track the health of servers and networks. A security flaw in its prediction graph page allows an authorized user to bypass normal data restrictions by injecting malicious commands. This could allow a user with low-level access to view or modify monitoring data they should not be able to reach, potentially impacting the integrity of system reports.

Technical details

A Livestatus injection vulnerability exists in Checkmk's user interface, specifically within the prediction graph page. The root cause is the improper neutralization of delimiters (CWE-140) where user-supplied service description values are interpolated into Livestatus queries without sufficient sanitization. An authenticated attacker with network access can exploit this by providing a crafted service name parameter to execute arbitrary Livestatus commands. This could lead to unauthorized data retrieval or modification within the monitoring core. The issue is addressed in versions 2.5.0b4, 2.4.0p26, and 2.3.0p47.

Affected products

  • Checkmk Checkmk < 2.5.0b4, < 2.4.0p26, < 2.3.0p47

Timeline

  • 2026-03-23: patched: Vendor fix released (Werk #17990)
  • 2026-04-10: disclosed: Initial CVE publication
  • 2026-04-20: advisory: NIST NVD analysis updated

References