Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
internet-facing-service-vulnerabilitywidely-deployed-product-advisory

Stored XSS Flaws in Checkmk 2.5.0 Beta Enable Cross-User Script Execution

Updated 3mo agoFirst seen Mar 31, 20262 sources

Checkmk disclosed two stored cross-site scripting vulnerabilities affecting Checkmk 2.5.0 beta releases before 2.5.0b2. The issues, tracked as CVE-2026-33276 and CVE-2026-20915, allow authenticated users to inject malicious JavaScript that later executes in other users’ browsers. Both flaws are classified as CWE-79 and are remotely exploitable with low attack complexity, though successful exploitation requires user interaction.

The first bug, CVE-2026-33276, affects the Unified Search feature and stems from unescaped host or service names, enabling users with permission to create hosts or services to plant persistent script payloads. The second, CVE-2026-20915, affects the Pending Changes sidebar and allows users with permission to create pending changes to inject stored JavaScript viewed by other users. Checkmk published vendor advisories for the flaws as Werk 19525 and Werk 19526, and both issues were reported to security@checkmk.com.

Share:
Stored XSS Flaws in Checkmk 2.5.0 Beta Enable Cross-User Script Execution
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Mar 31, 20263mo ago

CVE entries published for Checkmk stored XSS vulnerabilities

CVE-2026-33276 and CVE-2026-20915 were publicly recorded, classifying both issues as CWE-79 stored XSS vulnerabilities in Checkmk 2.5.0 beta before 2.5.0b2. The disclosures note authenticated attack paths and cross-user browser script execution risks.

Checkmk publishes vendor references for the two XSS issues

Checkmk published vendor advisories for the vulnerabilities as Werk 19525 and Werk 19526, documenting the stored XSS issues in Unified Search and the Pending Changes sidebar for affected 2.5.0 beta versions before 2.5.0b2.

Checkmk receives reports for two stored XSS flaws in 2.5.0 beta

On March 31, 2026, security@checkmk.com received reports for two stored cross-site scripting vulnerabilities affecting Checkmk 2.5.0 beta releases before 2.5.0b2. One flaw impacts Unified Search via unescaped host or service names (CVE-2026-33276), and the other affects the Pending Changes sidebar (CVE-2026-20915).

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

4 LINKEDOpen in app
Vulnerabilities
2 linked
Affected products
1 linked
Checkmk
Organizations
1 linked
Checkmk
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Stored XSS Flaws in Checkmk 2.5.0 Beta Enable Cross-User Script Execution | Mallory