CVE-2025-64998: Session hijacking via exposed session signing secret in distributed Checkmk setups
Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site with config sync enabled to hijack sessions on the central site by forging session cookies.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64998?
CVE-2025-64998 has a high severity rating due to the potential for session hijacking.
How do I fix CVE-2025-64998?
To fix CVE-2025-64998, upgrade to Checkmk version 2.4.0p23 or later, 2.3.0p45 or later, or 2.2.1 and above.
Who is affected by CVE-2025-64998?
CVE-2025-64998 affects administrators of Checkmk setups running vulnerable versions with config sync enabled.
What are the risks of CVE-2025-64998?
The primary risk of CVE-2025-64998 is the ability for malicious users to hijack sessions, potentially leading to unauthorized access.
How can I verify if my Checkmk instance is vulnerable to CVE-2025-64998?
You can verify vulnerability by checking if your Checkmk version is earlier than 2.4.0p23, 2.3.0p45, or exactly 2.2.0.