Catch up on the latest product updates, best practices, and expert insights from the Checkmk Conference #12 – Watch the livestream recordings now

Werk #22619: Fix permission check in mk-oracle when executing the OIC

Component Checks & agents
Title Fix permission check in mk-oracle when executing the OIC
Date Oct 5, 2026
Level Trivial Change
Class Security Fix
Compatibility Compatible - no manual interaction needed
Checkmk versions & editions
2.5.0p10 Checkmk Community, Checkmk Pro, Checkmk Ultimate, Checkmk Cloud, Checkmk Ultimate MT

As of this werk mk-oracle now also validates the permissions of user shared libraries, DLLs, and SQL query files such as those provided in the Oracle Instant Client. Unsafe files are rejected, preventing privilege escalation through resources that can be modified by an lower privileged user.

The permission checks can be disabled in Setup if required. On Windows, trusted entities can additionally be configured via safe lists provided by the Setup GUI.

Who is Affected

Systems running the agent with the mk-oracle plugin enabled. The attack requires the manipulation of shared object files in the referenced OIC within the host.

Affected Checkmk Versions

  • 2.5.0

Vulnerability Management

We have rated the issue with a CVSS Score of 5.2 Medium(CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H) and assigned CVE-2026-105331.

This issue was found by internal review.

Indicators of Compromise

We advise users to check their OIC installations for signs of tampering as well as their mk-oracle configuration yaml for malicious use_host_client path entries.

To the list of all Werks