CVE-2026-9549: Fix XSS in service discovery active check output
Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can configure active or custom checks to inject malicious HTML or JavaScript into check output that executes in the browser of an admin or a user with host read permissions when they run the check on the service discovery page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Checkmkto a version that resolves this vulnerability.Fixed in 2.5.0p5 - Upgrade
Upgrade
Checkmkto a version that resolves this vulnerability.Fixed in 2.4.0p31 - Upgrade
Upgrade
Checkmkto a version that resolves this vulnerability.Fixed in 2.3.0p48 - Upgrade
Upgrade
Checkmkto a version that resolves this vulnerability.Fixed in 2.2.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9549?
CVE-2026-9549 has a medium severity rating of 4.8 according to the CVSS score.
How do I fix CVE-2026-9549?
To fix CVE-2026-9549, update Checkmk to version 2.5.0p5, 2.4.0p31, or 2.3.0p48 or later.
What type of vulnerability is CVE-2026-9549?
CVE-2026-9549 is classified as a stored cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2026-9549?
Administrators who configure active or custom checks in affected versions of Checkmk are at risk from CVE-2026-9549.
When was CVE-2026-9549 published?
CVE-2026-9549 was published on June 8, 2026.