CVE-2026-105331

Checkmk: Untrusted Search Path (CVE-2026-105331)

mediumEPSS 0.1%

Description

Local privilege escalation in Checkmk 2.5.0 before 2.5.0p10 allows a user with access to edit the Oracle Instant Client referenced by the agent plugin 'mk-oracle' to escalate their privileges if an agent has this plugin enabled.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

CheckmkCheckmk
< 2.5.0p10fixed in 2.5.0p10

Metrics

5.2
Source: cna-v4
0.3 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
Show all metrics
Severity
medium
no public PoC known
0.1 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-10-08 15:17 UTC
CWE-426, CWE-829

Weakness classes (CWE)

  • CWE-426Base

    Untrusted Search Path

    The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

    cwe.mitre.org →
  • CWE-829Base

    Inclusion of Functionality from Untrusted Control Sphere

    The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-10-09 04:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-105331","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technical…
    • SSVC: {"id":"CVE-2026-105331","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technical…
  2. CVE Modified2026-10-08 16:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-105331","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technical…
  3. New CVE Received2026-10-08 15:17 UTC· security@checkmk.com
    • Description: Local privilege escalation in Checkmk 2.5.0 before 2.5.0p10 allows a user with access to edit the Oracle Instant Client referenced by the agent plugin 'mk-oracle' to escalate their privileges if an agent has this plugin enabled.
    • CVSS V4.0: AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    • CWE: CWE-426
    • CWE: CWE-829