CVE-2020-24908: Checkmk

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Checkmk before 1.6.0p17 allows local users to obtain SYSTEM privileges via a Trojan horse shell script in the %PROGRAMDATA%\checkmk\agent\local directory.

Affected products

  • Checkmk Checkmk: before 1.6.0 (fixed in 1.6.0); version 1.6.0 only

Published 2021-02-19. Last modified 2026-06-17.