CVE-2026-24095

EUVD-2026-6915
Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p21, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows users with the "Use WATO" permission to access the "Analyze configuration" page by directly navigating to its URL, bypassing the intended "Access analyze configuration" permission check. If these users also have the "Make changes, perform actions" permission, they can perform unauthorized actions such as disabling checks or acknowledging results.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
CheckmkCNA
5.3 MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
checkmkcheckmk
2.4.0 ≤
𝑥
≤ 2.4.0p20
CNA
checkmkcheckmk
2.3.0 ≤
𝑥
≤ 2.3.0p42
CNA
checkmkcheckmk
2.2.0
CNA
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
check-mk
bionic
needs-triage
jammy
dne
noble
dne
questing
dne
xenial
needs-triage