CVE-2026-92882

EUVD-2026-84349
Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an authenticated user who may view a host's configuration to read stored SNMP community strings, SNMPv3 auth and privacy pass phrases and IPMI passwords in clear text from GET responses, although the setup GUI never displays these values.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
CheckmkCNA
2.3 LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:L/SA:L
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
checkmkcheckmk
2.5.0 ≤
𝑥
≤ 2.5.0p14
CNA
checkmkcheckmk
2.4.0 ≤
𝑥
≤ 2.4.0p36
CNA
checkmkcheckmk
2.3.0 ≤
𝑥
≤ 2.3.0p50
CNA
checkmkcheckmk
2.2.0
CNA