HarborGuard / CVE
Back to search
HIGHCVE-2026-3466Published Modified CNA Checkmk

CVE-2026-3466: Cross-site scripting in dashlet title

Insufficient sanitization of dashboard dashlet title links in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0 allows an attacker with dashboard creation privileges to perform stored cross-site scripting (XSS) attacks by tricking a victim into clicking a crafted dashlet title link on a shared dashboard.

Metrics

CVSS v4.0
8.5
Severity
HIGH
Fixed in
2.3.0p46
Affected Products
1

Fix available

2.3.0p462.4.0p252.5.0
Affected packages
  • Checkmk GmbH / Checkmk
    2.2.0 · < 2.3.0p46 (from 2.3.0) · < 2.4.0p25 (from 2.4.0) · < 2.5.0 (from 2.5.0b1)
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:L/SA:N
CVE-2026-3466: Cross-site scripting in dashlet title | HarborGuard CVE