CVE-2026-92882 Details
Description
Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an authenticated user who may view a host's configuration to read stored SNMP community strings, SNMPv3 auth and privacy pass phrases and IPMI passwords in clear text from GET responses, although the setup GUI never displays these values.
A vulnerability exists in the host and folder configuration endpoints of the Checkmk REST API, affecting versions prior to 2.5.0p15, 2.4.0p37, 2.3.0p51, and 2.2.0 (EOL). This vulnerability allows an authenticated user with access to a host's configuration to retrieve sensitive information, including SNMP community strings, SNMPv3 authentication and privacy pass phrases, and IPMI passwords, in clear text via GET responses. The graphical user interface does not display these values, leaving them inadequately protected.
Users can update to Checkmk versions 2.5.0p15, 2.4.0p38, 2.3.0p51, or 3.0.0b1 to address this vulnerability. Instructions for updating can be found in the Checkmk documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 22, 2026CISA-ADP
Assessed Sep 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://checkmk.com/werk/20077 | [email protected] | Technical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Checkmk | < 2.5.0p15 < 2.4.0p37 < 2.3.0p51 2.2.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 22, 2026 | CVE Modified | CISA-ADP |
| Sep 22, 2026 | New CVE Received | [email protected] |
Volerion