Dear community,
This is an announcement for an upcoming security release of Checkmk.
On Monday, June 8th, we will publish a patch release for all currently supported versions of Checkmk: 2.3.0p48, 2.4.0p31, and 2.5.0p5.
The patch contains fixes for five vulnerabilities:
-
a Cross-Site-Scripting (XSS) vulnerability where authenticated, low-privilege users can attack other users (CVE-2026-7186)
-
an XSS vulnerability where authenticated, low-privilege users can attack other users (CVE-2026-8833)
-
an XSS vulnerability where authenticated, high-privilege users can attack other users (CVE-2026-8078)
-
an XSS vulnerability where authenticated, high-privilege users can attack other users (CVE-2026-9549)
-
2.5.0 only: an information disclosure issue in publicly shared dashboards (CVE-2026-7765)
Before applying this security patch, we recommend that users update to the current release: 2.3.0p47, 2.4.0p30, or 2.5.0p4. This reduces the risk of unrelated breaking changes that could delay the update.
If you have any questions, please feel free to reach out to security@checkmk.com.
Your Checkmk Team