CVE-2025-39666 is a local privilege escalation vulnerability affecting multiple versions of Checkmk, an open-source IT monitoring platform. The flaw exists in Checkmk 2.2.0 (end-of-life), 2.3.0 before 2.3.0p46, 2.4.0 before 2.4.0p25, and 2.5.0 beta before 2.5.0b3. An authenticated site user can exploit this by manipulating files in the site context that are processed when the omd administrative command is executed by root, resulting in privilege escalation to root access. The vulnerability carries a CVSS score of 7.3 (HIGH) with a local attack vector requiring low complexity and low privileges. User interaction is required for exploitation. Successful exploitation results in complete system compromise, as attackers would gain high-impact confidentiality, integrity, and availability violations through root-level access. There are no indications of active exploitation in the wild. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog, and community attention appears limited with an EPSS score of 0.00012 indicating minimal prevalence among disclosed vulnerabilities. Organizations running affected versions should prioritize patching to the specified fixed versions (2.3.0p46, 2.4.0p25, or 2.5.0b3 and later) to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.3.0, < 2.3.0p46CPE match | cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:* | ||
>= 2.4.0, < 2.4.0p25CPE match | cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:* | ||
2.2.0CPE matchmatch criteria | cpe:2.3:a:checkmk:checkmk:2.2.0:-:*:*:*:*:*:* | ||
2.2.0CPE matchmatch criteria | cpe:2.3:a:checkmk:checkmk:2.2.0:b1:*:*:*:*:*:* | ||
2.2.0CPE matchmatch criteria | cpe:2.3:a:checkmk:checkmk:2.2.0:b2:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.