Tribe29 develops Checkmk, a widely deployed infrastructure monitoring and observability platform used to track systems, networks, and applications at scale. The vendor's vulnerability exposure centers on its core monitoring product and associated appliance firmware, with recurring weaknesses in web-layer input handling, privilege boundaries, and information disclosure—typical of application software serving as a central management point. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tribe29 over time
Signals from CVEs in this vendor scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-40905HIGH The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which are Extension Packages, making | Mar 25, 2022 | 8.8 | 32 | NO | NO |
CVE-2022-48317CRITICAL Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 allowing an attacker to use expired session tokens when commu | Feb 20, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-46836HIGH PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker to inject and execute PHP | Feb 20, 2023 | 8.8 | 29 | NO | NO |
CVE-2023-31208HIGH Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for au | May 17, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-22294HIGH Privilege escalation in Tribe29 Checkmk Appliance before 1.6.4 allows authenticated site users to escalate privileges via incorrectly set permissions. | Apr 18, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-0284HIGH Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipulate files on the server. Checkmk <= 2.1.0p19, Checkmk <= 2.0 | Jan 26, 2023 | 8.1 | 25 | NO | NO |
CVE-2022-33912HIGH A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by the agent bakery (enterprise editions only) were not affected. | Jun 17, 2022 | 7.8 | 25 | NO | NO |
CVE-2023-31209HIGH Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrary command execution for authenticated users. | Aug 10, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-22318HIGH Denial of service in Webconf in Tribe29 Checkmk Appliance before 1.6.5. | May 15, 2023 | 7.5 | 24 | NO | NO |
CVE-2022-47909HIGH Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <= 2.0.0p28, and all versions of Checkmk 1.6.0 (EOL) allows an | Feb 20, 2023 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (32 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tribe29.
Media articles that mention a CVE ID that affects a product developed by Tribe29 — matched by CVE ID, not by vendor name.