CVE-2026-8078: Fix stored XSS in global settings change log
Stored cross-site scripting in the global settings change log in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can change global settings to store malicious HTML or JavaScript in changelog messages that executes in other users' browsers when they view the Activate Changes page or Audit log.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Checkmkto a version that resolves this vulnerability.Fixed in 2.5.0p5 - Upgrade
Upgrade
Checkmkto a version that resolves this vulnerability.Fixed in 2.4.0p31 - Upgrade
Upgrade
Checkmkto a version that resolves this vulnerability.Fixed in 2.3.0p48
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8078?
CVE-2026-8078 has a medium severity rating of 4.8 according to the CVSS scoring system.
How do I fix CVE-2026-8078?
To fix CVE-2026-8078, update to Checkmk versions 2.5.0p5 or later, 2.4.0p31 or later, and 2.3.0p48 or later.
What is the nature of the vulnerability CVE-2026-8078?
CVE-2026-8078 is a stored cross-site scripting (XSS) vulnerability that allows an administrator to inject malicious scripts in global settings changelogs.
Who is affected by CVE-2026-8078?
CVE-2026-8078 affects users and administrators of Checkmk versions below 2.5.0p5, 2.4.0p31, 2.3.0p48, and all versions 2.2.0.
What can attackers do with CVE-2026-8078?
Attackers can exploit CVE-2026-8078 by storing malicious HTML or JavaScript in changelog messages that execute in the browsers of other users.