Critical Privilege Escalation in Checkmk: Root Access at Risk
ID: d25d942a-edb6-5e01-abe4-09447d72e39f
STIX ID: report--d25d942a-edb6-5e01-abe4-09447d72e39f
Feed Name: securityonline.info
A critical Checkmk vulnerability (CVE-2025-39666, CVSS 9.3) allows local privilege escalation to root when administrative commands are executed with the system-wide omd command and a user can modify the site context. The advisory includes a detection script to check for a security flag, strongly warns against using omd as root until patched, and provides remediation steps: install the update, update all sites, stop sites before updating, and restore sites from within the site context if needed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
