CVE-2026-105331: Checkmk GmbH Checkmk
Medium severity, CVSS 5.2. EPSS: 0.1% chance of exploitation in the next 30 days.
Local privilege escalation in Checkmk 2.5.0 before 2.5.0p10 allows a user with access to edit the Oracle Instant Client referenced by the agent plugin 'mk-oracle' to escalate their privileges if an agent has this plugin enabled.
Affected products
- Checkmk GmbH Checkmk: from 2.5.0, before 2.5.0p10 (fixed in 2.5.0p10)
Published 2026-10-08. Last modified 2026-10-09.