CVE-2026-105331
Deferred Deferred - Pending Action

Local Privilege Escalation in Checkmk Agent Plugin

Vulnerability report for CVE-2026-105331, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Checkmk GmbH

Description

Local privilege escalation in Checkmk 2.5.0 before 2.5.0p10 allows a user with access to edit the Oracle Instant Client referenced by the agent plugin 'mk-oracle' to escalate their privileges if an agent has this plugin enabled.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Checkmk GmbH Checkmk 2.5.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-829 The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
CWE-426 The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a local privilege escalation vulnerability in Checkmk versions 2.5.0 before 2.5.0p10. It allows a user with permission to edit the Oracle Instant Client referenced by the 'mk-oracle' agent plugin to escalate their privileges if the plugin is enabled on an agent.

Detection Guidance

Inspect the mk-oracle plugin configuration in Checkmk for unauthorized modifications to Oracle Instant Client files or SQL queries. Checkmk Setup GUI can help review trusted entities on Windows. Look for unexpected changes in shared object files within the Oracle Instant Client directory.

Impact Analysis

An attacker with access to modify Oracle Instant Client files could exploit this to gain higher privileges on the system running the Checkmk agent with the mk-oracle plugin enabled. This could lead to unauthorized system access or control.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized privilege escalation. If exploited, it may lead to unauthorized access to sensitive data monitored by Checkmk, violating confidentiality requirements under these regulations. The local privilege escalation risk could enable attackers to bypass access controls, compromising data integrity and availability.

Mitigation Strategies

Upgrade Checkmk to version 2.5.0p10 or later. Disable the mk-oracle plugin if not needed. Review and remove any unauthorized files in the Oracle Instant Client directory. Ensure permission checks are enabled in the Setup.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105331. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart