CVE-2026-90990 - Livestatus injection via monitoring filter values
CVE ID :CVE-2026-90990
Published : Sept. 22, 2026, 10:43 a.m. | 26 minutes ago
Description :Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk <2.5.0p14 allows an authenticated user to inject additional Livestatus query headers, bypassing object visibility restrictions in count queries to infer information about hosts and services outside their contact groups and occupying web server and Livestatus workers for an attacker-controlled duration.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 22, 2026, 10:43 a.m. | 26 minutes ago
Description :Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk <2.5.0p14 allows an authenticated user to inject additional Livestatus query headers, bypassing object visibility restrictions in count queries to infer information about hosts and services outside their contact groups and occupying web server and Livestatus workers for an attacker-controlled duration.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...