CVE-2026-105331
mk-oracle: Local privilege escalation via malicious Oracle Instant Client
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Local privilege escalation in Checkmk 2.5.0 before 2.5.0p10 allows a user with access to edit the Oracle Instant Client referenced by the agent plugin 'mk-oracle' to escalate their privileges if an agent has this plugin enabled.
| CWE | CWE-426 CWE-829 |
| Vendor | checkmk gmbh |
| Product | checkmk |
| Published | Oct 8, 2026 |
| Last Updated | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for checkmk gmbh checkmk
Be the first to know when new unknown vulnerabilities affecting checkmk gmbh checkmk are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Checkmk GmbH / Checkmk
2.5.0 < 2.5.0p10