Upcoming Security Release 2.5.0p5, 2.4.0p31, 2.3.0p48

Dear community,

This is an announcement for an upcoming security release of Checkmk.

On Monday, June 8th, we will publish a patch release for all currently supported versions of Checkmk: 2.3.0p48, 2.4.0p31, and 2.5.0p5.

The patch contains fixes for five vulnerabilities:

  • a Cross-Site-Scripting (XSS) vulnerability where authenticated, low-privilege users can attack other users (CVE-2026-7186)

  • an XSS vulnerability where authenticated, low-privilege users can attack other users (CVE-2026-8833)

  • an XSS vulnerability where authenticated, high-privilege users can attack other users (CVE-2026-8078)

  • an XSS vulnerability where authenticated, high-privilege users can attack other users (CVE-2026-9549)

  • 2.5.0 only: an information disclosure issue in publicly shared dashboards (CVE-2026-7765)

Before applying this security patch, we recommend that users update to the current release: 2.3.0p47, 2.4.0p30, or 2.5.0p4. This reduces the risk of unrelated breaking changes that could delay the update.

If you have any questions, please feel free to reach out to security@checkmk.com.

Your Checkmk Team

1 Like

What time are you expecting to release the update?

We’re aiming for around noon CEST.

1 Like

The patches have been released. Links to the announcements: