CVE-2022-46303EPSS p62.4%

CVE-2022-46303CVE-2022-46303

checkmk / checkmk

Description

Command injection in SMS notifications in Tribe29 Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker with User Management permissions, as well as LDAP administrators in certain scenarios, to perform arbitrary commands within the context of the application's local permissions.

Scoring

CVSS 8.0 ()
VectorCVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS1.14% probability of exploitation · percentile 62.4% · 2026-06-19T12:03:05Z
Last modified2026-06-17
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.