Werk #22619: Fix permission check in mk-oracle when executing the OIC
| Component | Checks & agents | ||
| Title | Fix permission check in mk-oracle when executing the OIC | ||
| Date | Oct 5, 2026 | ||
| Level | Trivial Change | ||
| Class | Security Fix | ||
| Compatibility | Compatible - no manual interaction needed | ||
| Checkmk versions & editions |
|
As of this werk mk-oracle now also validates the permissions of user shared libraries, DLLs, and SQL query files such as those provided in the Oracle Instant Client. Unsafe files are rejected, preventing privilege escalation through resources that can be modified by an lower privileged user.
The permission checks can be disabled in Setup if required. On Windows, trusted entities can additionally be configured via safe lists provided by the Setup GUI.
Who is Affected
Systems running the agent with the mk-oracle plugin enabled. The attack requires the manipulation of shared object files in the referenced OIC within the host.
Affected Checkmk Versions
- 2.5.0
Vulnerability Management
We have rated the issue with a CVSS Score of 5.2 Medium(CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H) and assigned CVE-2026-105331.
This issue was found by internal review.
Indicators of Compromise
We advise users to check their OIC installations for signs of tampering as well as their mk-oracle configuration yaml for malicious use_host_client path entries.