CVE-2024-28826: Checkmk
High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.
Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and in Checkmk 2.0.0 (EOL) allows attackers with sufficient permissions to configure the check to read and write local files on the Checkmk site server.
Affected products
- Checkmk Checkmk: up to and including 2.0.0; version 2.1.0 only; version 2.2.0 only; version 2.3.0 only
Published 2024-05-29. Last modified 2026-06-17.