← Back to CVE search

CVE-2026-33276

Checkmk

Description

Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create hosts or services to execute arbitrary JavaScript in the browsers of other users performing searches in the Unified Search feature.

CVSS 5.4EPSS 0.14400000000000002%Risk 0.55
View source
Published
2026-03-31 15:16:14
Affected versions
<2.5.0b2
Type
Core software
Last modified
2026-07-24 21:10:00
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N