---
id: CVE-2026-33276
title: >-
  Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2
  allows authenticated users with permission to create hosts or services to
  execute arbitrary JavaScript in the browsers of other users performing
  searches in the Uni…
summary: >-
  Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2
  allows authenticated users with permission to create hosts or services to
  execute arbitrary JavaScript in the browsers of other users performing
  searches in the Uni…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: checkmk
product: checkmk
affected:
  - checkmk = 2.5.0
published: '2026-03-31'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-33276'
references:
  - url: 'https://checkmk.com/werk/19525'
    label: security@checkmk.com
tags:
  - nvd
epss: 0.00231
epssPercentile: 0.12452
ingestedAt: '2026-07-24T21:39:12.956Z'
---

## Overview

Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create hosts or services to execute arbitrary JavaScript in the browsers of other users performing searches in the Unified Search feature.

## Affected

- `checkmk = 2.5.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
