CVE-2026-92882 Overview
CVE-2026-92882 is an information disclosure vulnerability in the Checkmk monitoring platform. The flaw resides in the host and folder configuration endpoints of the REST API. Authenticated users with permission to view a host's configuration can retrieve stored credentials in clear text through GET responses. Exposed secrets include SNMP community strings, SNMPv3 authentication and privacy pass phrases, and IPMI passwords. The setup GUI never displays these values, so the API response bypasses the intended masking behavior. The vulnerability is tracked under [CWE-522: Insufficiently Protected Credentials].
Critical Impact
Authenticated users with host-view permissions can extract SNMP, SNMPv3, and IPMI credentials in plaintext through REST API GET requests, enabling lateral movement across monitored infrastructure.
Affected Products
- Checkmk versions prior to 2.5.0p15
- Checkmk versions prior to 2.4.0p37 and prior to 2.3.0p51
- Checkmk 2.2.0 (End of Life)
Discovery Timeline
- 2026-09-22 - CVE-2026-92882 published to NVD
- 2026-09-22 - Last updated in NVD database
Technical Details for CVE-2026-92882
Vulnerability Analysis
Checkmk stores sensitive credentials required to poll monitored systems, including SNMP community strings, SNMPv3 authentication and privacy pass phrases, and Intelligent Platform Management Interface (IPMI) passwords. These credentials must remain accessible to the monitoring engine but should never be returned to operator-facing interfaces in clear text.
The setup GUI enforces this expectation by masking credential fields. The REST API host and folder configuration endpoints do not enforce the same protection. GET requests against these endpoints serialize the full configuration object, including credential attributes, and return the plaintext values in the response body.
The issue affects the confidentiality of monitored infrastructure rather than the Checkmk server itself. An attacker who harvests SNMPv3 or IPMI credentials can authenticate directly to network devices and baseboard management controllers.
Root Cause
The host and folder configuration serializers in the REST API omit the redaction logic applied by the setup GUI. Credential fields are treated as regular configuration attributes and included verbatim in JSON responses. Any authenticated caller with read access to a host inherits access to that host's stored secrets, regardless of whether the role was intended to manage those secrets.
Attack Vector
Exploitation requires authenticated access to the Checkmk REST API with permission to view host configuration. An attacker issues a standard GET request to the affected host or folder endpoint and parses credential fields from the JSON response. No privilege escalation, chained exploit, or user interaction is required. Refer to the Checkmk Werk 20077 advisory for the vendor's technical description of the impacted endpoints and fix.
Detection Methods for CVE-2026-92882
Indicators of Compromise
- Unusual volumes of GET requests to Checkmk REST API paths under /objects/host_config/ and /objects/folder_config/ from a single authenticated user or API token.
- Access to host configuration endpoints from user accounts that historically only interact with dashboards or the monitoring views.
- SNMPv3 or IPMI authentication events on monitored devices originating from source addresses outside the Checkmk polling infrastructure.
Detection Strategies
- Review Checkmk web.log and audit logs for REST API calls to host and folder configuration endpoints, correlating user, token, and response size.
- Alert on API sessions that enumerate large numbers of hosts sequentially, which is consistent with credential harvesting.
- Cross-reference Checkmk API activity against network device authentication logs to detect stolen SNMPv3 or IPMI credential reuse.
Monitoring Recommendations
- Forward Checkmk API access logs to a centralized logging platform and retain them for incident review.
- Baseline normal REST API consumers, then flag deviations in endpoint patterns, request rates, and user agents.
- Monitor for new or modified API tokens in Checkmk, especially tokens attached to accounts with host configuration read rights.
How to Mitigate CVE-2026-92882
Immediate Actions Required
- Upgrade Checkmk to 2.5.0p15, 2.4.0p37, or 2.3.0p51 or later. Migrate away from the 2.2.0 branch, which is end of life.
- Rotate all SNMP community strings, SNMPv3 authentication and privacy pass phrases, and IPMI passwords stored in Checkmk after upgrading.
- Audit Checkmk user roles and revoke host configuration read permissions from accounts that do not require them.
Patch Information
The vendor addressed the issue in Checkmk 2.5.0p15, 2.4.0p37, and 2.3.0p51. Full details are published in Checkmk Werk 20077. Deployments on the 2.2.0 branch are not eligible for a fix and must be upgraded to a supported major version.
Workarounds
- Restrict REST API access at the network layer to trusted management hosts using firewall rules or a reverse proxy allow list.
- Remove host configuration view permissions from any role that does not strictly require them until patches are applied.
- Rotate exposed credentials on monitored devices and enforce least-privilege SNMPv3 and IPMI accounts scoped to read-only operations where feasible.
# Example: verify Checkmk site version after upgrade
omd version
# Example: list Checkmk users with configuration read rights for review
grep -R "admin\|host_config" ~/etc/check_mk/multisite.d/wato/
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
