Vulnerability Details CVE-2026-33456
Livestatus injection in the notification test mode in Checkmk <2.5.0b4 and <2.4.0p26 allows an authenticated user with access to the notification test page to inject arbitrary Livestatus commands via a crafted service description.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 15.6%
CVSS Severity
CVSS v3 Score 7.6
Products affected by CVE-2026-33456
-
cpe:2.3:a:checkmk:checkmk:2.4.0
-
cpe:2.3:a:checkmk:checkmk:2.5.0