Explore the latest product updates and best practices at our hybrid Checkmk Conference #12 from June 16-18, 2026 – Register here

Werk #17990: Potential livestatus injection in prediction graph page

Component User interface
Title Potential livestatus injection in prediction graph page
Date Mar 23, 2026
Level Trivial Change
Class Security Fix
Compatibility Compatible - no manual interaction needed
Checkmk versions & editions
2.6.0b1
Not yet released
Checkmk Community, Checkmk Pro, Checkmk Ultimate, Checkmk Cloud, Checkmk Ultimate MT
2.5.0b4 Checkmk Community, Checkmk Pro, Checkmk Ultimate, Checkmk Cloud, Checkmk Ultimate MT
2.4.0p26 Checkmk Community, Checkmk Pro, Checkmk Ultimate, Checkmk Cloud, Checkmk Ultimate MT
2.3.0p47
Not yet released
Checkmk Community, Checkmk Pro, Checkmk Ultimate, Checkmk Ultimate MT

Prior to this fix, the prediction graph page did not properly sanitize the user-supplied service description value before interpolating it into Livestatus queries. This allowed an authenticated user to inject arbitrary Livestatus commands via a crafted service name parameter.

This issue was found during internal review.

Affected Versions:

  • 2.5.0
  • 2.4.0
  • 2.3.0

Vulnerability Management:

We have rated the issue with a CVSS score of 5.3 (Medium) with the following CVSS vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N, and assigned CVE-2026-33457.

To the list of all Werks