Junglewise Threat Intelligence

CVE-2026-92882: Checkmk REST API credential exposure in host configuration

CVE-2026-92882 · Severity: info · Published 2026-09-22

Technologies: Checkmk. Vendors: Checkmk.

Executive brief

Checkmk is a monitoring platform used by IT teams to track systems and infrastructure. A vulnerability in its REST API allows authenticated users to view sensitive credentials—including SNMP community strings, authentication passphrases, and IPMI passwords—in plain text when querying host configuration endpoints, despite these credentials being hidden in the web interface.

Technical details

The REST API host and folder configuration GET endpoints insufficiently protect sensitive credential fields, returning SNMP community strings, SNMPv3 auth/privacy passphrases, and IPMI passwords in cleartext. This affects authenticated users with permissions to view host configuration. The vulnerability requires authentication and host viewing privileges, making it an information disclosure risk for deployments where API access is shared across teams or where credential exposure could be leveraged for lateral movement.

Affected products

  • Checkmk Checkmk 2.5.0 before p15, 2.4.0 before p37, 2.3.0 before p51, 2.2.0

Timeline

  • 2026-09-22: disclosed: Advisory published

References

Related threats