CVE-2026-90990
Deferred Deferred - Pending Action

Improper Newline Neutralization in Checkmk API

Vulnerability report for CVE-2026-90990, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-22

Last updated on: 2026-09-22

Assigner: Checkmk GmbH

Description

Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk <2.5.0p14 allows an authenticated user to inject additional Livestatus query headers, bypassing object visibility restrictions in count queries to infer information about hosts and services outside their contact groups and occupying web server and Livestatus workers for an attacker-controlled duration.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-22
Last Modified
2026-09-22
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
checkmk checkmk 2.5.0p14
checkmk checkmk to 3.0.0b1 (exc)
checkmk checkmk 3.0.0b1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-93 The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper neutralization of newlines in filter values in the monitoring host and service list APIs of Checkmk versions before 2.5.0p14. An authenticated user can inject additional Livestatus query headers to bypass object visibility restrictions in count queries. This allows them to infer information about hosts and services outside their assigned contact groups and to prolong server and worker processing times.

Detection Guidance

To detect this vulnerability, check your Checkmk version using the command 'omd version' or by inspecting the web interface under 'Setup > General > Information'. If your version is 2.5.0p14 or earlier, the system is vulnerable.

Impact Analysis

An attacker with authenticated access could access sensitive monitoring data about hosts or services they should not see. They could also cause performance degradation by occupying web server and Livestatus workers for extended periods, potentially disrupting monitoring operations.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Exposure of host or service information outside permitted groups may result in compliance breaches, potential fines, and reputational damage.

Mitigation Strategies

Upgrade Checkmk to version 3.0.0b1 or later immediately. No manual interaction is required for compatibility after upgrading. If upgrading is not possible, restrict authenticated user access to the monitoring host and service list APIs as a temporary measure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90990. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart