CVE-2026-3466 PUBLISHED

Cross-site scripting in dashlet title

Assigner: Checkmk
Reserved: 03.03.2026 Published: 07.04.2026 Updated: 07.04.2026

Insufficient sanitization of dashboard dashlet title links in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0b3 allows an attacker with dashboard creation privileges to perform stored cross-site scripting (XSS) attacks by tricking a victim into clicking a crafted dashlet title link on a shared dashboard.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:L/SA:N
CVSS Score: 8.5

Product Status

Vendor Checkmk GmbH
Product Checkmk
Versions Default: unaffected
  • Version 2.2.0 is affected
  • affected from 2.3.0 to 2.3.0p46 (excl.)
  • affected from 2.4.0 to 2.4.0p25 (excl.)
  • affected from 2.5.0b1 to 2.5.0b3 (excl.)

Credits

  • Alex Williams (Pellera Technologies) reporter

References

Problem Types

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE

Impacts

  • CAPEC-592: Stored XSS