SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-14852

MEDIUM · CVSS 5.2 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Checkmk versions prior to 2.5.0p9, 2.4.0p34, and 2.3.0p49 are vulnerable to privilege escalation, allowing local unprivileged users to execute arbitrary commands as root by manipulating the mk_sap_hana agent plugin. This vulnerability arises when the plugin, which is designed to interface with SAP HANA, derives instance identifiers from the process list without an explicit database configuration. Organizations using affected versions, particularly those running the mk_sap_hana plugin with root privileges, should prioritize patching to mitigate potential exploitation.

CVE
CVE-2026-14852
Severity
MEDIUM
CVSS
5.2
EPSS
0.22%

Original NVD Description

Privilege escalation in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows a local unprivileged user to execute arbitrary commands as root by starting a process crafted to look like a SAP HANA instance. Without an explicit database configuration, the mk_sap_hana agent plugin derives instance identifiers from the process list and uses them to build a command executed with elevated privileges (requires the plugin to run as root with RUNAS=agent).