CVE-2024-13723: Checkmk Nagvis
High severity, CVSS 7.2. EPSS: 1.3% chance of exploitation in the next 30 days.
The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP.
Affected products
- Checkmk Nagvis
Published 2025-02-04. Last modified 2026-06-17.