CVE-2025-64998: Checkmk
High severity, CVSS 7.2. EPSS: 0.3% chance of exploitation in the next 30 days.
Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site with config sync enabled to hijack sessions on the central site by forging session cookies.
Affected products
- Checkmk Checkmk: version 2.2.0 only; version 2.3.0 only; version 2.4.0 only
Published 2026-03-24. Last modified 2026-06-17.