{"id":"CVE-2026-92882","title":"Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an authenticated user who may view a host's configuration to read store…","summary":"Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an authenticated user who may view a host's configuration to read store…","severity":"low","cvss":2.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:L/SA:L","cwe":["CWE-522"],"vendor":"Checkmk GmbH","product":"Checkmk","affected":["Checkmk >= 2.5.0 < 2.5.0p15","Checkmk >= 2.4.0 < 2.4.0p37","Checkmk >= 2.3.0 < 2.3.0p51","Checkmk 2.2.0"],"published":"2026-09-22","updated":"2026-09-22","sourceUpdated":"2026-09-22T14:17:17.950","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92882","references":[{"url":"https://checkmk.com/werk/20077","label":"security@checkmk.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-22T13:05:05.230960Z"},"cvssSource":"cna","ingestedAt":"2026-09-22T11:02:22.249Z","slug":"CVE-2026-92882","body":"## Overview\n\nInsufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an authenticated user who may view a host's configuration to read stored SNMP community strings, SNMPv3 auth and privacy pass phrases and IPMI passwords in clear text from GET responses, although the setup GUI never displays these values.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":13,"depthScoreParts":{"impact":12.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}