CVE-2026-33456: Potential livestatus injection in notification test
Livestatus injection in the notification test mode in Checkmk <2.5.0b4 and <2.4.0p26 allows an authenticated user with access to the notification test page to inject arbitrary Livestatus commands via a crafted service description.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33456?
CVE-2026-33456 is classified as a medium severity vulnerability due to the potential for authenticated users to perform Livestatus command injection.
How do I fix CVE-2026-33456?
To mitigate CVE-2026-33456, update Checkmk to version 2.5.0b4 or 2.4.0p26 or later.
Who is affected by CVE-2026-33456?
CVE-2026-33456 affects authenticated users of Checkmk versions prior to 2.5.0b4 and 2.4.0p26.
What functionality is compromised by CVE-2026-33456?
CVE-2026-33456 allows an authenticated user access to the notification test page to inject arbitrary Livestatus commands.
Is CVE-2026-33456 exploitable without authentication?
No, CVE-2026-33456 requires authentication to access the notification test page for exploitation.