{"id":"CVE-2021-40904","title":"The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code","summary":"The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code. As a result, remote code execution is achieved. Success…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-276"],"vendor":"checkmk","product":"checkmk","affected":["checkmk >= 1.5.0, < 1.6.0"],"patched":["checkmk 1.6.0"],"published":"2022-03-25","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-40904","references":[{"url":"https://github.com/Edgarloyola/CVE-2021-40904","label":"cve@mitre.org"},{"url":"http://checkmk.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/Edgarloyola/CVE-2021-40904","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.03692,"epssPercentile":0.89236,"ingestedAt":"2026-07-06T17:03:24.116Z","exploits":{"github":1,"githubRepos":["https://github.com/Edgarloyola/CVE-2021-40904"],"checkedAt":"2026-09-21T15:24:44.113Z"},"exploitAvailable":true,"slug":"CVE-2021-40904","body":"## Overview\n\nThe web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code. As a result, remote code execution is achieved. Successful exploitation requires access to the web management interface, either with valid credentials or with a hijacked session by a user with the role of administrator.\n\n## Affected\n\n- `checkmk >= 1.5.0, < 1.6.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `checkmk 1.6.0`","depth":"midnight","depthScore":61,"depthScoreParts":{"impact":48.4,"likelihood":0.7,"exploitation":12,"ransomware":0},"changes":[{"seq":4569,"id":"CVE-2021-40904","ts":1788887191379,"field":"exploit_available","old":"false","new":"true"},{"seq":3452,"id":"CVE-2021-40904","ts":1788886308429,"field":"exploit_available","old":"true","new":"false"},{"seq":2306,"id":"CVE-2021-40904","ts":1788882978069,"field":"exploit_available","old":"false","new":"true"},{"seq":1335,"id":"CVE-2021-40904","ts":1788882390125,"field":"exploit_available","old":"true","new":"false"},{"seq":449,"id":"CVE-2021-40904","ts":1788881826050,"field":"exploit_available","old":"false","new":"true"}]}