CVE-2026-8833
EUVD-2026-3505308.06.2026, 13:16
Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an authenticated user to bypass URL validation and inject malicious URLs such as javascript: URIs, resulting in cross-site scripting when another user interacts with the crafted link.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| checkmk | checkmk | 2.2.0 |
| checkmk | checkmk | 2.2.0:b1 |
| checkmk | checkmk | 2.2.0:b2 |
| checkmk | checkmk | 2.2.0:b3 |
| checkmk | checkmk | 2.2.0:b4 |
| checkmk | checkmk | 2.2.0:b5 |
| checkmk | checkmk | 2.2.0:b6 |
| checkmk | checkmk | 2.2.0:b7 |
| checkmk | checkmk | 2.2.0:b8 |
| checkmk | checkmk | 2.2.0:i1 |
| checkmk | checkmk | 2.2.0:p1 |
| checkmk | checkmk | 2.2.0:p10 |
| checkmk | checkmk | 2.2.0:p11 |
| checkmk | checkmk | 2.2.0:p12 |
| checkmk | checkmk | 2.2.0:p13 |
| checkmk | checkmk | 2.2.0:p14 |
| checkmk | checkmk | 2.2.0:p15 |
| checkmk | checkmk | 2.2.0:p16 |
| checkmk | checkmk | 2.2.0:p17 |
| checkmk | checkmk | 2.2.0:p18 |
| checkmk | checkmk | 2.2.0:p19 |
| checkmk | checkmk | 2.2.0:p2 |
| checkmk | checkmk | 2.2.0:p20 |
| checkmk | checkmk | 2.2.0:p21 |
| checkmk | checkmk | 2.2.0:p22 |
| checkmk | checkmk | 2.2.0:p23 |
| checkmk | checkmk | 2.2.0:p24 |
| checkmk | checkmk | 2.2.0:p25 |
| checkmk | checkmk | 2.2.0:p26 |
| checkmk | checkmk | 2.2.0:p27 |
| checkmk | checkmk | 2.2.0:p28 |
| checkmk | checkmk | 2.2.0:p29 |
| checkmk | checkmk | 2.2.0:p3 |
| checkmk | checkmk | 2.2.0:p30 |
| checkmk | checkmk | 2.2.0:p31 |
| checkmk | checkmk | 2.2.0:p32 |
| checkmk | checkmk | 2.2.0:p33 |
| checkmk | checkmk | 2.2.0:p34 |
| checkmk | checkmk | 2.2.0:p35 |
| checkmk | checkmk | 2.2.0:p36 |
| checkmk | checkmk | 2.2.0:p37 |
| checkmk | checkmk | 2.2.0:p38 |
| checkmk | checkmk | 2.2.0:p39 |
| checkmk | checkmk | 2.2.0:p4 |
| checkmk | checkmk | 2.2.0:p40 |
| checkmk | checkmk | 2.2.0:p41 |
| checkmk | checkmk | 2.2.0:p42 |
| checkmk | checkmk | 2.2.0:p43 |
| checkmk | checkmk | 2.2.0:p44 |
| checkmk | checkmk | 2.2.0:p45 |
| checkmk | checkmk | 2.2.0:p46 |
| checkmk | checkmk | 2.2.0:p47 |
| checkmk | checkmk | 2.2.0:p5 |
| checkmk | checkmk | 2.2.0:p6 |
| checkmk | checkmk | 2.2.0:p7 |
| checkmk | checkmk | 2.2.0:p8 |
| checkmk | checkmk | 2.2.0:p9 |
| checkmk | checkmk | 2.3.0 |
| checkmk | checkmk | 2.3.0:b1 |
| checkmk | checkmk | 2.3.0:b2 |
| checkmk | checkmk | 2.3.0:b3 |
| checkmk | checkmk | 2.3.0:b4 |
| checkmk | checkmk | 2.3.0:b5 |
| checkmk | checkmk | 2.3.0:b6 |
| checkmk | checkmk | 2.3.0:p1 |
| checkmk | checkmk | 2.3.0:p10 |
| checkmk | checkmk | 2.3.0:p11 |
| checkmk | checkmk | 2.3.0:p12 |
| checkmk | checkmk | 2.3.0:p13 |
| checkmk | checkmk | 2.3.0:p14 |
| checkmk | checkmk | 2.3.0:p15 |
| checkmk | checkmk | 2.3.0:p16 |
| checkmk | checkmk | 2.3.0:p17 |
| checkmk | checkmk | 2.3.0:p18 |
| checkmk | checkmk | 2.3.0:p19 |
| checkmk | checkmk | 2.3.0:p2 |
| checkmk | checkmk | 2.3.0:p20 |
| checkmk | checkmk | 2.3.0:p21 |
| checkmk | checkmk | 2.3.0:p22 |
| checkmk | checkmk | 2.3.0:p23 |
| checkmk | checkmk | 2.3.0:p24 |
| checkmk | checkmk | 2.3.0:p25 |
| checkmk | checkmk | 2.3.0:p26 |
| checkmk | checkmk | 2.3.0:p27 |
| checkmk | checkmk | 2.3.0:p28 |
| checkmk | checkmk | 2.3.0:p29 |
| checkmk | checkmk | 2.3.0:p3 |
| checkmk | checkmk | 2.3.0:p30 |
| checkmk | checkmk | 2.3.0:p31 |
| checkmk | checkmk | 2.3.0:p32 |
| checkmk | checkmk | 2.3.0:p33 |
| checkmk | checkmk | 2.3.0:p34 |
| checkmk | checkmk | 2.3.0:p35 |
| checkmk | checkmk | 2.3.0:p36 |
| checkmk | checkmk | 2.3.0:p37 |
| checkmk | checkmk | 2.3.0:p38 |
| checkmk | checkmk | 2.3.0:p39 |
| checkmk | checkmk | 2.3.0:p4 |
| checkmk | checkmk | 2.3.0:p40 |
| checkmk | checkmk | 2.3.0:p41 |
| checkmk | checkmk | 2.3.0:p42 |
| checkmk | checkmk | 2.3.0:p43 |
| checkmk | checkmk | 2.3.0:p44 |
| checkmk | checkmk | 2.3.0:p45 |
| checkmk | checkmk | 2.3.0:p46 |
| checkmk | checkmk | 2.3.0:p47 |
| checkmk | checkmk | 2.3.0:p5 |
| checkmk | checkmk | 2.3.0:p6 |
| checkmk | checkmk | 2.3.0:p7 |
| checkmk | checkmk | 2.3.0:p8 |
| checkmk | checkmk | 2.3.0:p9 |
| checkmk | checkmk | 2.4.0 |
| checkmk | checkmk | 2.4.0 |
| checkmk | checkmk | 2.4.0:b1 |
| checkmk | checkmk | 2.4.0:b2 |
| checkmk | checkmk | 2.4.0:b3 |
| checkmk | checkmk | 2.4.0:b4 |
| checkmk | checkmk | 2.4.0:b5 |
| checkmk | checkmk | 2.4.0:b6 |
| checkmk | checkmk | 2.4.0:p1 |
| checkmk | checkmk | 2.4.0:p10 |
| checkmk | checkmk | 2.4.0:p11 |
| checkmk | checkmk | 2.4.0:p12 |
| checkmk | checkmk | 2.4.0:p13 |
| checkmk | checkmk | 2.4.0:p14 |
| checkmk | checkmk | 2.4.0:p15 |
| checkmk | checkmk | 2.4.0:p16 |
| checkmk | checkmk | 2.4.0:p17 |
| checkmk | checkmk | 2.4.0:p18 |
| checkmk | checkmk | 2.4.0:p19 |
| checkmk | checkmk | 2.4.0:p2 |
| checkmk | checkmk | 2.4.0:p20 |
| checkmk | checkmk | 2.4.0:p21 |
| checkmk | checkmk | 2.4.0:p22 |
| checkmk | checkmk | 2.4.0:p23 |
| checkmk | checkmk | 2.4.0:p24 |
| checkmk | checkmk | 2.4.0:p25 |
| checkmk | checkmk | 2.4.0:p26 |
| checkmk | checkmk | 2.4.0:p27 |
| checkmk | checkmk | 2.4.0:p28 |
| checkmk | checkmk | 2.4.0:p29 |
| checkmk | checkmk | 2.4.0:p3 |
| checkmk | checkmk | 2.4.0:p30 |
| checkmk | checkmk | 2.4.0:p4 |
| checkmk | checkmk | 2.4.0:p5 |
| checkmk | checkmk | 2.4.0:p6 |
| checkmk | checkmk | 2.4.0:p7 |
| checkmk | checkmk | 2.4.0:p8 |
| checkmk | checkmk | 2.4.0:p9 |
| checkmk | checkmk | 2.5.0 |
| checkmk | checkmk | 2.5.0:b1 |
| checkmk | checkmk | 2.5.0:b2 |
| checkmk | checkmk | 2.5.0:b3 |
| checkmk | checkmk | 2.5.0:p1 |
| checkmk | checkmk | 2.5.0:p2 |
| checkmk | checkmk | 2.5.0:p3 |
| checkmk | checkmk | 2.5.0:p4 |
𝑥
= Vulnerable software versions
Vulnerability Media Exposure
References