CVE-2026-33455

Livestatus injection in the monitoring quicksearch in Checkmk <2.5.0b4 allows an authenticated attacker to inject livestatus commands via the search query due to insufficient input sanitization in search filter plugins.
CVSS

No CVSS.

References
Configurations

No configuration.

History

10 Apr 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-10 09:16

Updated : 2026-04-13 15:02


NVD link : CVE-2026-33455

Mitre link : CVE-2026-33455

CVE.ORG link : CVE-2026-33455


JSON object : View

Products Affected

No product.

CWE
CWE-140

Improper Neutralization of Delimiters