CVE-2023-0284: Checkmk

High severity, CVSS 8.1. EPSS: 0.9% chance of exploitation in the next 30 days.

Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipulate files on the server. Checkmk <= 2.1.0p19, Checkmk <= 2.0.0p32, and all versions of Checkmk 1.6.0 (EOL) are affected.

Affected products

  • Checkmk Checkmk: version 2.0.0 only; version 2.1.0 only
  • TRIBE29 Checkmk: from 1.6.0, before 2.0.0 (fixed in 2.0.0)

Published 2023-01-26. Last modified 2026-06-17.