CVE-2026-14852: Checkmk GmbH Checkmk

Medium severity, CVSS 5.2. EPSS: 0.2% chance of exploitation in the next 30 days.

Privilege escalation in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows a local unprivileged user to execute arbitrary commands as root by starting a process crafted to look like a SAP HANA instance. Without an explicit database configuration, the mk_sap_hana agent plugin derives instance identifiers from the process list and uses them to build a command executed with elevated privileges (requires the plugin to run as root with RUNAS=agent).

Affected products

  • Checkmk GmbH Checkmk: from 2.5.0, before 2.5.0p9 (fixed in 2.5.0p9); from 2.4.0, before 2.4.0p34 (fixed in 2.4.0p34); from 2.3.0, before 2.3.0p49 (fixed in 2.3.0p49); version 2.2.0 only

Published 2026-07-14. Last modified 2026-07-29.