Junglewise Threat Intelligence

CVE-2026-7186: Checkmk stored XSS in URL dashboard widget

CVE-2026-7186 · Severity: info · CVSS 8.5 · Published 2026-06-08

Technologies: Checkmk GmbH Checkmk.

Executive brief

Checkmk is an IT infrastructure monitoring platform used to track the health of servers and networks. A security flaw in its dashboard system allows a user with dashboard editing rights to embed malicious scripts into shared views. If another user views the compromised dashboard, the script could execute in their browser, potentially allowing an attacker to steal session information or perform actions on the victim's behalf.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the URL dashboard widget of Checkmk. The component failed to properly validate URI schemes, allowing the use of 'javascript:' or other dangerous schemes. An attacker with dashboard editing permissions can save a malicious URL that executes arbitrary JavaScript when the dashboard is viewed by other users. This requires the victim to open the shared dashboard via the 'Monitor' or 'Customize' menus. The issue is resolved in versions 2.5.0p5, 2.4.0p31, and 2.3.0p48 by restricting the widget to only accept 'http' and 'https' schemes.

Affected products

  • Checkmk GmbH Checkmk < 2.5.0p5, < 2.4.0p31, < 2.3.0p48, all 2.2.0 versions

Timeline

  • 2026-04-29: patched: Fix released in multiple versions via Werk #17991
  • 2026-06-08: disclosed: CVE published to NVD

References