CVE-2026-33276: XSS in Unified Search via Unescaped Host/Service Names
Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create hosts or services to execute arbitrary JavaScript in the browsers of other users performing searches in the Unified Search feature.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33276?
CVE-2026-33276 has been classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2026-33276?
To fix CVE-2026-33276, upgrade Checkmk to version 2.5.0b2 or later.
Who is affected by CVE-2026-33276?
Authenticated users with permission to create hosts or services in Checkmk versions prior to 2.5.0b2 are affected by CVE-2026-33276.
What type of vulnerability is CVE-2026-33276?
CVE-2026-33276 is classified as a cross-site scripting (XSS) vulnerability.
What are the consequences of CVE-2026-33276?
CVE-2026-33276 allows an attacker to execute arbitrary JavaScript in the browsers of users who perform searches in the Unified Search feature.