PatchSiren cyber security CVE debrief
CVE-2026-92882 Checkmk GmbH CVE debrief
CVE-2026-92882 is a medium-severity vulnerability affecting Checkmk's REST API. Insufficiently protected credentials in host and folder configuration endpoints allow authenticated users with host configuration view permissions to read sensitive credentials in clear text. System administrators and security teams should assess exposure, particularly in environments with multiple REST API users, and prioritize remediation by updating Checkmk to a patched version. The vulnerability impacts versions prior to 2.5.0p15, 2.4.0p38, 2.3.0p51, and 2.2.0. Authenticated users may read SNMP community strings, SNMPv3 auth and privacy pass phrases, and IPMI passwords in clear text from GET
- Vendor
- Checkmk GmbH
- Product
- Checkmk
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-22
- Original CVE updated
- 2026-10-05
- Advisory published
- 2026-09-22
- Advisory updated
- 2026-10-05
Who should care
System administrators and security teams responsible for Checkmk installations, particularly those with REST API access configured, should assess exposure and prioritize remediation. This vulnerability may impact environments where multiple administrators have access to host configuration views in the REST API.
Why it matters
CVE-2026-92882 is a medium-severity vulnerability in Checkmk's REST API that could allow authenticated users with host configuration view permissions to read sensitive credentials in clear text. System administrators and security teams should assess exposure, particularly in environments with multiple REST API users, and prioritize remediation by updating Checkmk to a patched version.
- Potential unauthorized disclosure of sensitive credentials including SNMP community strings, SNMPv3 auth and privacy pass phrases, and IPMI passwords.
- Possible misuse of obtained credentials for unauthorized access or lateral movement within the network.
- Need for verification of current Checkmk version and exposure to REST API configuration views.
- Priority for updating Checkmk to a patched version as soon as possible.
Technical summary
CVE-2026-92882 affects Checkmk versions prior to 2.5.0p15, 2.4.0p38, 2.3.0p51, and 2.2.0. The vulnerability involves insufficiently protected credentials in the host and folder configuration endpoints of the REST API. An authenticated user who can view a host's configuration may be able to read stored SNMP community strings, SNMPv3 auth and privacy pass phrases, and IPMI passwords in clear text from GET responses.
Defensive priority
Authenticated users with host configuration view permissions may have been able to read sensitive credentials including SNMP community strings, SNMPv3 auth and privacy pass phrases, and IPMI passwords in clear text from REST API responses prior to Checkmk version 2.5.0p15, 2.4.0p38, 2.3.0p51, or 2.2.0.
Recommended defensive actions
- Review and update Checkmk installations to version 2.5.0p15 or later, 2.4.0p38 or later, 2.3.0p51 or later, as applicable.
- Restrict access to host configuration views in the REST API to only necessary personnel.
- Monitor REST API usage for suspicious activity related to host and folder configuration endpoints.
- Consider implementing additional security measures such as encryption for sensitive credentials in transit and at rest.
- Verify current Checkmk version and exposure to REST API configuration views.
- Prioritize updating Checkmk to a patched version as soon as possible.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE Program and NIST NVD records indicate insufficiently protected credentials in Checkmk REST API endpoints for host and folder configuration, affecting versions prior to 2.5.0p15, 2.4.0p38, 2.3.0p51, and 2.2.0. Authenticated users with view permissions for a host's configuration could potentially read SNMP community strings, SNMPv3 auth and privacy pass phrases, and IPMI passwords in clear text from GET responses.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-92882 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-92882
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-92882 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92882
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://checkmk.com/werk/20077
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.