Junglewise Threat Intelligence

CVE-2026-8833: Checkmk cross-site scripting via URL validation bypass

CVE-2026-8833 · Severity: info · CVSS 8.5 · Published 2026-06-08

Technologies: Checkmk GmbH Checkmk.

Executive brief

Checkmk, a popular IT infrastructure monitoring platform, contains a security flaw in how it validates web links. An authorized user can bypass security checks to insert malicious links into the system. If another user clicks on one of these links, an attacker could potentially take control of their session or steal sensitive information.

Technical details

A cross-site scripting (XSS) vulnerability exists in Checkmk due to improper neutralization of HTML-encoded characters within the URL validation function. An authenticated attacker can bypass the validation mechanism by using encoded characters to inject malicious 'javascript:' URIs. When a victim interacts with the crafted link, the malicious script executes in the context of their browser session. This can lead to full session compromise or unauthorized actions performed on behalf of the victim. The issue is fixed in versions 2.5.0p5, 2.4.0p31, and 2.3.0p48.

Affected products

  • Checkmk GmbH Checkmk < 2.5.0p5, < 2.4.0p31, < 2.3.0p48, all 2.2.0 versions

Timeline

  • 2026-05-18: patched: Vendor released fix (Werk #20002)
  • 2026-06-08: disclosed: CVE published to NVD

References