Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://checkmk.com/werk/20077 |
|
Tue, 22 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an authenticated user who may view a host's configuration to read stored SNMP community strings, SNMPv3 auth and privacy pass phrases and IPMI passwords in clear text from GET responses, although the setup GUI never displays these values. | |
| Title | Redact SNMP community, SNMPv3 pass phrases, and IPMI password in host config REST API GET responses | |
| First Time appeared |
Checkmk
Checkmk checkmk |
|
| Weaknesses | CWE-522 | |
| CPEs | cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Checkmk
Checkmk checkmk |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Checkmk
Published:
Updated: 2026-09-22T13:05:16.125Z
Reserved: 2026-09-17T08:34:06.088Z
Link: CVE-2026-92882
Updated: 2026-09-22T13:05:09.113Z
Status : Deferred
Published: 2026-09-22T11:17:26.497
Modified: 2026-09-22T14:17:17.950
Link: CVE-2026-92882
No data.
OpenCVE Enrichment
Updated: 2026-09-22T12:00:14Z
-
CWE-522
Insufficiently Protected Credentials