CVE-2025-39666 PUBLISHED

omd: Local privilege escalation when executing omd commands as root

Assigner: Checkmk
Reserved: 16.04.2025 Published: 07.04.2026 Updated: 07.04.2026

Local privilege escalation in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0b3 allows a site user to escalate their privileges to root, by manipulating files in the site context that are processed when the omd administrative command is run by root.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9.3

Product Status

Vendor Checkmk GmbH
Product Checkmk
Versions Default: unaffected
  • Version 2.2.0 is affected
  • affected from 2.3.0 to 2.3.0p46 (excl.)
  • affected from 2.4.0 to 2.4.0p25 (excl.)
  • affected from 2.5.0b1 to 2.5.0b3 (excl.)

References

Problem Types

  • CWE-426: Untrusted Search Path CWE
  • CWE-829: Inclusion of Functionality from Untrusted Control Sphere CWE

Impacts

  • CAPEC-471: Search Order Hijacking
  • CAPEC-17: Accessing, Modifying or Executing Executable Files