Skip to main content
Vulnerability Database/CVE-2026-90990

CVE-2026-90990: Checkmk Information Disclosure Vulnerability

CVE-2026-90990 is an information disclosure flaw in Checkmk that lets authenticated users bypass visibility restrictions to access unauthorized host and service data. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-90990 Overview

CVE-2026-90990 is a CRLF injection vulnerability [CWE-93] in Checkmk affecting versions prior to 2.5.0p14. The flaw resides in the monitoring host and service list APIs, which fail to neutralize newline characters within filter values. An authenticated user can inject additional Livestatus query headers, bypassing object visibility restrictions enforced by contact groups. Attackers exploit this to infer information about hosts and services outside their authorized scope and to occupy web server and Livestatus workers for arbitrary durations, degrading monitoring availability.

Critical Impact

Authenticated users can bypass Livestatus contact-group visibility controls to enumerate restricted hosts and services, and can tie up backend workers to disrupt monitoring operations.

Affected Products

  • Checkmk versions prior to 2.5.0p14
  • Checkmk monitoring host list API
  • Checkmk monitoring service list API

Discovery Timeline

  • 2026-09-22 - CVE-2026-90990 published to the National Vulnerability Database (NVD)
  • 2026-09-22 - Last updated in NVD database

Technical Details for CVE-2026-90990

Vulnerability Analysis

Checkmk exposes host and service list APIs that accept filter parameters. These filters are translated into Livestatus query headers before being sent to the monitoring backend. The APIs do not strip or escape newline characters (\n, \r\n) inside filter values. As a result, an authenticated caller can embed additional Livestatus headers directly into the query stream.

Livestatus is Checkmk's line-oriented query protocol where each header occupies its own line. Injected headers such as additional Filter:, Or:, And:, Stats:, or WaitTimeout: directives alter query semantics after object-visibility filters have been applied. This lets the attacker widen the result set beyond their contact groups or force the backend to block on long-running conditions.

The impact splits into two categories: information disclosure through count queries that reveal the existence of hosts and services the user should not see, and resource exhaustion by holding web server threads and Livestatus workers open for attacker-controlled durations.

Root Cause

The root cause is improper neutralization of CRLF sequences in user-supplied filter values before they are concatenated into a line-delimited protocol payload [CWE-93]. Checkmk trusted the filter parameters to be single-line values and passed them into the Livestatus query builder without sanitization.

Attack Vector

Exploitation requires network access to the Checkmk web interface and a valid authenticated session with any privilege level. The attacker submits a crafted request to the host or service list endpoint with a filter value containing embedded newline characters followed by additional Livestatus header lines. See the Checkmk Work Item #19604 advisory for protocol-level details.

Detection Methods for CVE-2026-90990

Indicators of Compromise

  • HTTP requests to Checkmk host or service list API endpoints containing URL-encoded newline sequences (%0A, %0D%0A) within filter parameter values.
  • Unusually long-running requests to the monitoring APIs that hold web server workers open beyond normal query completion times.
  • Livestatus query logs showing unexpected Filter:, Stats:, or WaitTimeout: headers originating from low-privilege user sessions.

Detection Strategies

  • Inspect Checkmk apache.log and Livestatus query logs for filter values containing raw or encoded CRLF characters.
  • Correlate authenticated user sessions with count-query responses that reference hosts or services outside the user's contact group membership.
  • Alert on sustained increases in concurrent Livestatus worker occupancy or web server thread saturation without a matching increase in scheduled checks.

Monitoring Recommendations

  • Enable verbose Livestatus query logging on Checkmk sites and forward the logs to a centralized SIEM for retention and search.
  • Track per-user API request rates and response latencies to surface accounts issuing anomalously slow or numerous filter queries.
  • Baseline normal API filter parameter lengths and character sets, then alert on deviations that include control characters.

How to Mitigate CVE-2026-90990

Immediate Actions Required

  • Upgrade all Checkmk sites to version 2.5.0p14 or later without delay.
  • Audit existing Checkmk user accounts and remove credentials that are no longer required to reduce the authenticated attack surface.
  • Review recent access logs on the host and service list APIs for filter values containing CRLF sequences and investigate any matches.

Patch Information

Checkmk resolved this vulnerability in release 2.5.0p14. The fix is documented in Checkmk Work Item #19604. Administrators should apply the vendor patch through standard Checkmk update procedures and restart affected sites to ensure the corrected filter parser is loaded.

Workarounds

  • Restrict network access to the Checkmk web interface using firewall rules or a reverse proxy that limits exposure to trusted management networks.
  • Deploy a reverse proxy or web application firewall rule that rejects requests to the monitoring APIs when filter parameters contain %0A or %0D sequences.
  • Enforce strong authentication and least-privilege role assignments for Checkmk users until the patch is applied.
bash
# Example reverse proxy rule (nginx) to block CRLF in Checkmk filter parameters
location ~ ^/[^/]+/check_mk/api/ {
    if ($args ~* "(%0A|%0D|%0a|%0d)") {
        return 400;
    }
    proxy_pass http://checkmk_backend;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.