---
id: CVE-2026-8078
title: >-
  Stored cross-site scripting in the global settings change log in Checkmk
  <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator
  who can change global settings to store malicious HTML or JavaScript in
  changelog mes…
summary: >-
  Stored cross-site scripting in the global settings change log in Checkmk
  <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator
  who can change global settings to store malicious HTML or JavaScript in
  changelog mes…
severity: medium
cvss: 4.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: checkmk
product: checkmk
affected:
  - checkmk = 2.2.0
  - checkmk = 2.3.0
  - checkmk = 2.4.0
  - checkmk = 2.5.0
published: '2026-06-08'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T22:10:00.247'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-8078'
references:
  - url: 'https://checkmk.com/werk/17992'
    label: security@checkmk.com
tags:
  - nvd
epss: 0.00242
epssPercentile: 0.14053
ingestedAt: '2026-10-06T22:23:15.933Z'
---

## Overview

Stored cross-site scripting in the global settings change log in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can change global settings to store malicious HTML or JavaScript in changelog messages that executes in other users' browsers when they view the Activate Changes page or Audit log.

## Affected

- `checkmk = 2.2.0`
- `checkmk = 2.3.0`
- `checkmk = 2.4.0`
- `checkmk = 2.5.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
