PatchSiren cyber security CVE debrief
CVE-2025-39666 Checkmk GmbH CVE debrief
A local privilege escalation vulnerability exists in Checkmk versions 2.2.0 (EOL), 2.3.0 before 2.3.0p46, 2.4.0 before 2.4.0p25, and 2.5.0 (beta) before 2.5.0b3. This vulnerability allows a site user to escalate their privileges to root by manipulating files in the site context that are processed when the `omd` administrative command is run by root.
- Vendor
- Checkmk GmbH
- Product
- Checkmk
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-07
- Original CVE updated
- 2026-10-05
- Advisory published
- 2026-04-07
- Advisory updated
- 2026-10-05
Who should care
Checkmk administrators and users with site user privileges should assess their exposure and take necessary actions to mitigate this vulnerability. This includes verifying the affected versions, restricting access to the `omd` administrative command, and implementing additional security controls. Operators and security teams responsible for Checkmk instances should prioritize patching or mitigating this vulnerability to prevent potential exploitation.
Why it matters
This vulnerability requires immediate attention from Checkmk administrators and users with site user privileges, as it allows for local privilege escalation to root. Defenders should prioritize patching or mitigating this vulnerability to prevent potential exploitation.
- Potential privilege escalation to root for site users
- Increased risk of lateral movement and unauthorized access
- Possible disruption of Checkmk services and monitoring capabilities
- Required verification of user and file system access controls
Technical summary
The vulnerability exists in Checkmk versions 2.2.0 (EOL), 2.3.0 before 2.3.0p46, 2.4.0 before 2.4.0p25, and 2.5.0 (beta) before 2.5.0b3. A site user can exploit this vulnerability by manipulating files in the site context that are processed when the `omd` administrative command is run by root, allowing them to escalate their privileges to root. This vulnerability requires immediate attention from Checkmk administrators and users with site user privileges, as it allows for local privilege escalation to root. Defenders should prioritize patching or mitigating this vulnerability to prevent potential exploitation.
Defensive priority
Defenders should prioritize patching or mitigating this vulnerability, especially for Checkmk instances with untrusted or semi-trusted site users.
Recommended defensive actions
- Patch Checkmk instances to the latest version, specifically 2.3.0p46, 2.4.0p25, or 2.5.0b3 and later.
- Restrict access to the `omd` administrative command to trusted users only.
- Monitor site user activity for suspicious file manipulation.
- Implement additional security controls, such as SELinux or AppArmor, to limit the impact of a potential exploit.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability, including its description, CVSS score, and affected versions. Checkmk administrators should verify the affected versions 2.2.0 (EOL), 2.3.0 before 2.3.0p46, 2.4.0 before 2.4.0p25, and 2.5.0 (beta) before 2.5.0b3. The vulnerability allows a site user to escalate their privileges to root by manipulating files in the site context that are processed when the `omd` administrative command is run by root. Evidence is limited to public CVE and NVD records.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-39666 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-39666
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-39666 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39666
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://checkmk.com/werk/18891
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.