CVE-2026-33457: Potential livestatus injection in prediction graph page
Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allows an authenticated user to inject arbitrary Livestatus commands via a crafted service name parameter due to insufficient sanitization of the service description value.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33457?
CVE-2026-33457 is classified as a medium severity vulnerability due to the potential for unauthorized command injection.
How do I fix CVE-2026-33457?
To mitigate CVE-2026-33457, upgrade Checkmk to versions 2.5.0b5 or later, 2.4.0p27 or later, or 2.3.0p48 or later.
Who is affected by CVE-2026-33457?
CVE-2026-33457 affects all authenticated users of Checkmk versions prior to 2.5.0b5, 2.4.0p27, and 2.3.0p48.
What types of attacks can CVE-2026-33457 enable?
CVE-2026-33457 enables authenticated users to perform Livestatus command injections via manipulated service names.
Is there a workaround for CVE-2026-33457?
There is no recommended workaround for CVE-2026-33457 other than upgrading to secure versions of the software.