CVE-2026-20915

Source
https://cve.org/CVERecord?id=CVE-2026-20915
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-20915.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-20915
Downstream
Published
2026-03-31T13:51:02.358Z
Modified
2026-08-12T03:51:41.492694411Z
Severity
  • 8.5 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:L/SA:N CVSS Calculator
Summary
Stored cross-site scripting in Pending Changes sidebar
Details

Stored cross-site scripting (XSS) in Checkmk version 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create pending changes to inject malicious JavaScript into the Pending Changes sidebar, which will execute in the browsers of other users viewing the sidebar.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "2.5.0b1"
                },
                {
                    "fixed": "2.5.0b2"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "introduced": "2.5.0b1"
                },
                {
                    "fixed": "2.5.0b2"
                }
            ],
            "source": "CPE_FIELD"
        },
        {
            "extracted_events": [
                {
                    "fixed": "2.5.0b2"
                }
            ],
            "source": "DESCRIPTION"
        }
    ],
    "cna_assigner": "Checkmk",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/20xxx/CVE-2026-20915.json"
}
References

Affected packages

Git / github.com/checkmk/checkmk

Affected ranges

Type
GIT
Repo
https://github.com/checkmk/checkmk
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.5.0-b1"
        },
        {
            "last_affected": "2.5.0-b1"
        }
    ],
    "source": "CPE_STRING",
    "cpe": "cpe:2.3:a:checkmk:checkmk:2.5.0:b1:*:*:*:*:*:*"
}

Affected versions

2.*
2.5.0-b1
v2.*
v2.5.0p1
v2.5.0p1-rc2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-20915.json"