Vulnerability Description
Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allows an authenticated user to inject arbitrary Livestatus commands via a crafted service name parameter due to insufficient sanitization of the service description value.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Checkmk | Checkmk | 2.3.0 |
Related Weaknesses (CWE)
References
- https://checkmk.com/werk/17990Vendor Advisory
FAQ
What is CVE-2026-33457?
CVE-2026-33457 is a vulnerability with a CVSS score of 6.3 (MEDIUM). Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allows an authenticated user to inject arbitrary Livestatus commands via a crafted service name paramete...
How severe is CVE-2026-33457?
CVE-2026-33457 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-33457?
Check the references section above for vendor advisories and patch information. Affected products include: Checkmk Checkmk.