{"id":"CVE-2021-40906","title":"CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone","summary":"CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device with HTML content an…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"checkmk","product":"checkmk","affected":["checkmk >= 1.5.0, < 1.6.0","checkmk = 1.6.0","checkmk = 1.6.0b10","checkmk = 1.6.0b11","checkmk = 1.6.0p10","checkmk = 1.6.0p17","checkmk = 1.6.0p18"],"patched":["checkmk 1.6.0"],"published":"2022-03-25","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-40906","references":[{"url":"https://github.com/Edgarloyola/CVE-2021-40906","label":"cve@mitre.org"},{"url":"http://checkmk.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/Edgarloyola/CVE-2021-40906","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.00989,"epssPercentile":0.61013,"ingestedAt":"2026-07-06T17:03:24.117Z","exploits":{"github":1,"githubRepos":["https://github.com/Edgarloyola/CVE-2021-40906"],"checkedAt":"2026-09-23T07:13:21.759Z"},"exploitAvailable":true,"slug":"CVE-2021-40906","body":"## Overview\n\nCheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device with HTML content and interpreted by the browser (such as JavaScript or other client-side scripts) or to steal the session cookies of a user who has previously authenticated via a man in the middle. Successful exploitation requires access to the web service resource without authentication.\n\n## Affected\n\n- `checkmk >= 1.5.0, < 1.6.0`\n- `checkmk = 1.6.0`\n- `checkmk = 1.6.0b10`\n- `checkmk = 1.6.0b11`\n- `checkmk = 1.6.0p10`\n- `checkmk = 1.6.0p17`\n- `checkmk = 1.6.0p18`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `checkmk 1.6.0`","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":33.6,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[{"seq":4571,"id":"CVE-2021-40906","ts":1788887191389,"field":"exploit_available","old":"false","new":"true"},{"seq":3454,"id":"CVE-2021-40906","ts":1788886308439,"field":"exploit_available","old":"true","new":"false"},{"seq":2308,"id":"CVE-2021-40906","ts":1788882978078,"field":"exploit_available","old":"false","new":"true"},{"seq":1337,"id":"CVE-2021-40906","ts":1788882390135,"field":"exploit_available","old":"true","new":"false"},{"seq":451,"id":"CVE-2021-40906","ts":1788881826062,"field":"exploit_available","old":"false","new":"true"}]}