CVE-2026-3466: Cross-site scripting in dashlet title
Insufficient sanitization of dashboard dashlet title links in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0 allows an attacker with dashboard creation privileges to perform stored cross-site scripting (XSS) attacks by tricking a victim into clicking a crafted dashlet title link on a shared dashboard.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3466?
CVE-2026-3466 is classified as a medium severity vulnerability due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2026-3466?
To fix CVE-2026-3466, you should update Checkmk to version 2.3.0p46 or later, 2.4.0p25 or later, or 2.5.0b3 or later.
What types of systems are affected by CVE-2026-3466?
CVE-2026-3466 affects Checkmk versions 2.2.0, versions 2.3.0 prior to 2.3.0p46, 2.4.0 prior to 2.4.0p25, and 2.5.0 beta prior to 2.5.0b3.
What is the nature of the vulnerability in CVE-2026-3466?
CVE-2026-3466 involves insufficient sanitization of dashboard dashlet title links, allowing for stored cross-site scripting.
Who can exploit CVE-2026-3466?
An attacker with dashboard creation privileges can exploit CVE-2026-3466 to perform stored cross-site scripting attacks.