Session hijacking via exposed session signing secret in distributed Checkmk setups
Vulnerability Description
Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site with config sync enabled to hijack sessions on the central site by forging session cookies.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-64998
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Lisa Gnedt (SBA Research)
References
More from Checkmk GmbH
View All →Affected Vendor
Checkmk GmbH
View all reports →