PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-39666 Checkmk GmbH CVE debrief

A local privilege escalation vulnerability exists in Checkmk versions 2.2.0 (EOL), 2.3.0 before 2.3.0p46, 2.4.0 before 2.4.0p25, and 2.5.0 (beta) before 2.5.0b3. This vulnerability allows a site user to escalate their privileges to root by manipulating files in the site context that are processed when the `omd` administrative command is run by root.

Vendor
Checkmk GmbH
Product
Checkmk
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-07
Original CVE updated
2026-10-05
Advisory published
2026-04-07
Advisory updated
2026-10-05

Who should care

Checkmk administrators and users with site user privileges should assess their exposure and take necessary actions to mitigate this vulnerability. This includes verifying the affected versions, restricting access to the `omd` administrative command, and implementing additional security controls. Operators and security teams responsible for Checkmk instances should prioritize patching or mitigating this vulnerability to prevent potential exploitation.

Why it matters

This vulnerability requires immediate attention from Checkmk administrators and users with site user privileges, as it allows for local privilege escalation to root. Defenders should prioritize patching or mitigating this vulnerability to prevent potential exploitation.

  • Potential privilege escalation to root for site users
  • Increased risk of lateral movement and unauthorized access
  • Possible disruption of Checkmk services and monitoring capabilities
  • Required verification of user and file system access controls

Technical summary

The vulnerability exists in Checkmk versions 2.2.0 (EOL), 2.3.0 before 2.3.0p46, 2.4.0 before 2.4.0p25, and 2.5.0 (beta) before 2.5.0b3. A site user can exploit this vulnerability by manipulating files in the site context that are processed when the `omd` administrative command is run by root, allowing them to escalate their privileges to root. This vulnerability requires immediate attention from Checkmk administrators and users with site user privileges, as it allows for local privilege escalation to root. Defenders should prioritize patching or mitigating this vulnerability to prevent potential exploitation.

Defensive priority

Defenders should prioritize patching or mitigating this vulnerability, especially for Checkmk instances with untrusted or semi-trusted site users.

Recommended defensive actions

  • Patch Checkmk instances to the latest version, specifically 2.3.0p46, 2.4.0p25, or 2.5.0b3 and later.
  • Restrict access to the `omd` administrative command to trusted users only.
  • Monitor site user activity for suspicious file manipulation.
  • Implement additional security controls, such as SELinux or AppArmor, to limit the impact of a potential exploit.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, including its description, CVSS score, and affected versions. Checkmk administrators should verify the affected versions 2.2.0 (EOL), 2.3.0 before 2.3.0p46, 2.4.0 before 2.4.0p25, and 2.5.0 (beta) before 2.5.0b3. The vulnerability allows a site user to escalate their privileges to root by manipulating files in the site context that are processed when the `omd` administrative command is run by root. Evidence is limited to public CVE and NVD records.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-39666 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-39666

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-39666 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39666

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.