---
id: CVE-2021-40904
title: >-
  The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0)
  allows a misconfiguration of the web-app Dokuwiki (installed by default),
  which allows embedded php code
summary: >-
  The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0)
  allows a misconfiguration of the web-app Dokuwiki (installed by default),
  which allows embedded php code. As a result, remote code execution is
  achieved. Success…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-276
vendor: checkmk
product: checkmk
affected:
  - 'checkmk >= 1.5.0, < 1.6.0'
patched:
  - checkmk 1.6.0
published: '2022-03-25'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-40904'
references:
  - url: 'https://github.com/Edgarloyola/CVE-2021-40904'
    label: cve@mitre.org
  - url: 'http://checkmk.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/Edgarloyola/CVE-2021-40904'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.03692
epssPercentile: 0.89218
ingestedAt: '2026-07-06T17:03:24.116Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/Edgarloyola/CVE-2021-40904'
  checkedAt: '2026-09-23T07:13:21.758Z'
exploitAvailable: true
---

## Overview

The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code. As a result, remote code execution is achieved. Successful exploitation requires access to the web management interface, either with valid credentials or with a hijacked session by a user with the role of administrator.

## Affected

- `checkmk >= 1.5.0, < 1.6.0`

## Remediation

Upgrade past the affected range:

- `checkmk 1.6.0`
