← Back to search

CVE-2026-90990

— UNSCORED

Published 2026-09-22 · Updated 2026-09-22

AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.

NVD description

Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk <2.5.0p14 allows an authenticated user to inject additional Livestatus query headers, bypassing object visibility restrictions in count queries to infer information about hosts and services outside their contact groups and occupying web server and Livestatus workers for an attacker-controlled duration.

Weaknesses

CWE-93

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.