CVE-2025-39666: omd: Local privilege escalation when executing omd commands as root
Local privilege escalation in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0b3 allows a site user to escalate their privileges to root, by manipulating files in the site context that are processed when the omd administrative command is run by root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39666?
CVE-2025-39666 has a high severity as it allows local privilege escalation to root.
How do I fix CVE-2025-39666?
To fix CVE-2025-39666, update Checkmk to version 2.3.0p46 or later, or 2.4.0p25 or later, or 2.5.0b3 or later.
What versions of Checkmk are affected by CVE-2025-39666?
CVE-2025-39666 affects Checkmk versions 2.2.0, versions 2.3.0 before 2.3.0p46, versions 2.4.0 before 2.4.0p25, and all beta versions before 2.5.0b3.
What are the potential impacts of CVE-2025-39666?
The impact of CVE-2025-39666 includes potential unauthorized privilege escalation, allowing an attacker to gain root access.
Is CVE-2025-39666 present on EOL Checkmk versions?
Yes, CVE-2025-39666 is present in Checkmk 2.2.0, which is an end-of-life (EOL) version.