Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-39666

25
FAUCET Score

CVE-2025-39666 is a local privilege escalation vulnerability affecting multiple versions of Checkmk, an open-source IT monitoring platform. The flaw exists in Checkmk 2.2.0 (end-of-life), 2.3.0 before 2.3.0p46, 2.4.0 before 2.4.0p25, and 2.5.0 beta before 2.5.0b3. An authenticated site user can exploit this by manipulating files in the site context that are processed when the omd administrative command is executed by root, resulting in privilege escalation to root access. The vulnerability carries a CVSS score of 7.3 (HIGH) with a local attack vector requiring low complexity and low privileges. User interaction is required for exploitation. Successful exploitation results in complete system compromise, as attackers would gain high-impact confidentiality, integrity, and availability violations through root-level access. There are no indications of active exploitation in the wild. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog, and community attention appears limited with an EPSS score of 0.00012 indicating minimal prevalence among disclosed vulnerabilities. Organizations running affected versions should prioritize patching to the specified fixed versions (2.3.0p46, 2.4.0p25, or 2.5.0b3 and later) to mitigate the risk.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.3.0, < 2.3.0p46CPE match
cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*
>= 2.4.0, < 2.4.0p25CPE match
cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*
2.2.0CPE matchmatch criteria
cpe:2.3:a:checkmk:checkmk:2.2.0:-:*:*:*:*:*:*
2.2.0CPE matchmatch criteria
cpe:2.3:a:checkmk:checkmk:2.2.0:b1:*:*:*:*:*:*
2.2.0CPE matchmatch criteria
cpe:2.3:a:checkmk:checkmk:2.2.0:b2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

9.3CRITICAL

CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
HIGH
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.12%
Probability of exploitation in next 30 days
EPSS Percentile
2.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0012 is in the 11th percentile among its peer group of 759 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

checkmk.com / werk/18891
Vendor Advisory