CVE-2025-64998
EUVD-2025-20895824.03.2026, 12:16
Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site with config sync enabled to hijack sessions on the central site by forging session cookies.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| checkmk | checkmk | 2.4.0 ≤ 𝑥 ≤ 2.4.0p22 | CNA |
| checkmk | checkmk | 2.3.0 ≤ 𝑥 ≤ 2.3.0p44 | CNA |
| checkmk | checkmk | 2.2.0 | CNA |
Ubuntu Releases
Common Weakness Enumeration
References