---
id: CVE-2026-90990
title: >-
  Improper neutralization of newlines in filter values in the monitoring host
  and service list APIs in Checkmk <2.5.0p14 allows an authenticated user to
  inject additional Livestatus query headers, bypassing object visibility
  restrictions i…
summary: >-
  Improper neutralization of newlines in filter values in the monitoring host
  and service list APIs in Checkmk <2.5.0p14 allows an authenticated user to
  inject additional Livestatus query headers, bypassing object visibility
  restrictions i…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'
cwe:
  - CWE-93
vendor: Checkmk GmbH
product: Checkmk
affected:
  - Checkmk >= 2.5.0 < 2.5.0p14
published: '2026-09-22'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T14:17:17.830'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90990'
references:
  - url: 'https://checkmk.com/werk/19604'
    label: security@checkmk.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-22T13:04:36.772264Z'
cvssSource: cna
ingestedAt: '2026-09-22T11:02:22.249Z'
epss: 0.00421
epssPercentile: 0.33775
---

## Overview

Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk <2.5.0p14 allows an authenticated user to inject additional Livestatus query headers, bypassing object visibility restrictions in count queries to infer information about hosts and services outside their contact groups and occupying web server and Livestatus workers for an attacker-controlled duration.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
