CVE-2026-33455: Livestatus injection in monitoring quicksearch
Published Apr 10, 2026
·Updated
Livestatus injection in the monitoring quicksearch in Checkmk <2.5.0b4 allows an authenticated attacker to inject livestatus commands via the search query due to insufficient input sanitization in search filter plugins.
Affected Software
4 affected components
Checkmk Checkmk<2.5.0b4
Checkmk Checkmk=2.5.0-b1
Checkmk Checkmk=2.5.0-b2
Checkmk Checkmk=2.5.0-b3
Event History
Apr 10, 2026
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-33455?
CVE-2026-33455 is classified as a medium severity vulnerability due to the potential for command injection.
2
How do I fix CVE-2026-33455?
To fix CVE-2026-33455, upgrade Checkmk to version 2.5.0b5 or later which addresses the input sanitization issue.
3
Who is affected by CVE-2026-33455?
CVE-2026-33455 affects all users running Checkmk versions prior to 2.5.0b5.
4
What kind of attack can exploit CVE-2026-33455?
CVE-2026-33455 can be exploited by an authenticated attacker injecting livestatus commands through the search query.
5
Is an update mandatory for CVE-2026-33455?
Yes, updating to the latest version is mandatory to mitigate the risks associated with CVE-2026-33455.