Checkmk

Checkmk

Top 1M site
VDPActive RecognitionPartial Safe Harbor

Program Details

Checkmk's disclosure programme covers its monitoring codebase, appliance, Kubernetes cluster collector, Grafana datasource and websites. Reports go to [email protected] in English or German with a description and proof of concept, and the security team replies within a few business days. Anonymous submissions are welcome and reporters can be credited by name. Checkmk aims to address reported issues within 90 days; there is no committed bounty, only a possible token of appreciation.

Allows Disclosure
Yes
Disclosure Window
90 days

Rules & Testing

Excluded Methods

DosSocial EngineeringPhishingPhysical Access

Scope (6 targets)

  • Checkmk codebase other
  • Checkmk K8s cluster collector other
  • Checkmk Grafana datasource other
  • Checkmk appliance hardware
  • checkmk.com website and its subdomains web
  • tribe29.com website and its subdomains web

Out of Scope

Self-XSS that cannot be exploited against other users, (Distributed) Denial of service attacks against the in-scope domains, machines running Checkmk, or the Checkmk appliances, Lack of HSTS enforcement for Checkmk web applications, Missing cookie flags without a PoC on how this can be exploited, Missing security headers without a PoC on how this can be exploited, HTTP request smuggling without any proven business impact, Blind SSRF without proven business impact (DNS pingback only is not sufficient), HTTP Host header manipulation without a proven business impact, Disclosed and/or misconfigured API keys without proven business impact, Verbose error and log messages that do not reveal personal data or secrets, Clickjacking attacks with low or no impact, Version disclosure without a PoC on how it can be exploited, Open ports without a PoC on how it can be exploited, Weak SSL configurations and SSL/TLS scan reports, Arbitrary file upload without proof of the existence of the uploaded file, Best practices violations (password complexity, expiration, re-use) with low or no impact, Installation of malicious software on machines running Checkmk or on the Checkmk appliances, Physical attacks against the Checkmk appliances, Social engineering attacks against Checkmk employees, partners, or customers, Anything related to email spoofing, SPF, DMARC or DKIM, Email bombing, Side-channel attacks

Security

PGP Key
https://checkmk.com/.well-known/pgp-key.txt
Preferred Languages
English, German

security.txt

Contact
mailto:[email protected]
Encryption
https://checkmk.com/.well-known/pgp-key.txt
Policy
https://checkmk.com/vulnerability-disclosure-policy
Expires
Oct 1, 2026
View raw security.txt →