VYPR
High severity7.2NVD Advisory· Published Mar 24, 2026· Updated May 12, 2026

CVE-2025-64998

CVE-2025-64998

Description

Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site with config sync enabled to hijack sessions on the central site by forging session cookies.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Checkmk/Checkmkllm-fuzzy2 versions
    <2.4.0p23, <2.3.0p45, <2.2.0+ 1 more
    • (no CPE)range: <2.4.0p23, <2.3.0p45, <2.2.0
    • (no CPE)range: 2.4.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.