CVE-2026-90990 PUBLISHED

Livestatus injection via monitoring filter values

Assigner: Checkmk
Reserved: 14.09.2026 Published: 22.09.2026 Updated: 22.09.2026

Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk <2.5.0p14 allows an authenticated user to inject additional Livestatus query headers, bypassing object visibility restrictions in count queries to infer information about hosts and services outside their contact groups and occupying web server and Livestatus workers for an attacker-controlled duration.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor Checkmk GmbH
Product Checkmk
Versions Default: unaffected
  • affected from 2.5.0 to 2.5.0p14 (excl.)

References

Problem Types

  • CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection') CWE

Impacts

  • CAPEC-15: Command Delimiters