Checkmk Livestatus Injection Vulnerability in Monitoring Quicksearch

Vulnerability

A livestatus injection vulnerability has been identified in the monitoring quicksearch feature of Checkmk versions prior to 2.5.0b4. This vulnerability allows authenticated attackers to inject livestatus commands through the search query, exploiting inadequate input sanitization in the search filter plugins.

Impact

Exploitation of this vulnerability allows for livestatus command injection, which could potentially be used to manipulate monitoring data or behavior.

Remediation

Users can upgrade to Checkmk versions 2.6.0b1 or 2.5.0b4 to address this vulnerability.

Added: Apr 10, 2026, 10:55 AM
Updated: Apr 10, 2026, 10:55 AM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
2.5
exploitability
5.2
remediation
7.7
relevance
5.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.