Description
Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an authenticated user who may view a host's configuration to read stored SNMP community strings, SNMPv3 auth and privacy pass phrases and IPMI passwords in clear text from GET responses, although the setup GUI never displays these values.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://checkmk.com/werk/20077 |
|
History
Tue, 22 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an authenticated user who may view a host's configuration to read stored SNMP community strings, SNMPv3 auth and privacy pass phrases and IPMI passwords in clear text from GET responses, although the setup GUI never displays these values. | |
| Title | Redact SNMP community, SNMPv3 pass phrases, and IPMI password in host config REST API GET responses | |
| First Time appeared |
Checkmk
Checkmk checkmk |
|
| Weaknesses | CWE-522 | |
| CPEs | cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Checkmk
Checkmk checkmk |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Checkmk
Published:
Updated: 2026-09-22T10:42:59.432Z
Reserved: 2026-09-17T08:34:06.088Z
Link: CVE-2026-92882
No data.
Status : Deferred
Published: 2026-09-22T11:17:26.497
Modified: 2026-09-22T11:17:26.603
Link: CVE-2026-92882
No data.
OpenCVE Enrichment
Updated: 2026-09-22T11:30:09Z
Weaknesses
-
CWE-522
Insufficiently Protected Credentials