{"id":"CVE-2026-92882","published":"2026-09-22T11:17:26.497","lastModified":"2026-09-22T14:17:17.950","description":"Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an authenticated user who may view a host's configuration to read stored SNMP community strings, SNMPv3 auth and privacy pass phrases and IPMI passwords in clear text from GET responses, although the setup GUI never displays these values.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-522"],"vendors":[],"products":[],"references":[{"url":"https://checkmk.com/werk/20077","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}