CVE-2026-14852 Details
Description
Privilege escalation in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows a local unprivileged user to execute arbitrary commands as root by starting a process crafted to look like a SAP HANA instance. Without an explicit database configuration, the mk_sap_hana agent plugin derives instance identifiers from the process list and uses them to build a command executed with elevated privileges (requires the plugin to run as root with RUNAS=agent).
A privilege escalation vulnerability has been identified in Checkmk versions 2.5.0 prior to 2.5.0p9, 2.4.0 prior to 2.4.0p34, 2.3.0 prior to 2.3.0p49, and 2.2.0 (EOL). This vulnerability allows a local unprivileged user to execute arbitrary commands as root by initiating a process designed to resemble a SAP HANA instance. In the absence of a specific database configuration, the mk_sap_hana agent plugin extracts instance identifiers from the process list and uses them to construct a command that is executed with elevated privileges. This exploitation requires the plugin to operate as root with RUNAS=agent.
Users can update to Checkmk versions 2.5.0p9, 2.4.0p34, or 2.3.0p49. Instructions for updating can be found in the Checkmk documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 14, 2026CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://checkmk.com/werk/20104 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Checkmk | 2.5.0 (semver) 2.4.0 (semver) 2.3.0 (semver) 2.2.0 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 29, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | New CVE Received | [email protected] |
Volerion