CVE-2026-8593

EUVD-2026-46165
Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to view and modify BI packs and rules
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
CheckmkCNA
5.3 MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 10%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
checkmkcheckmk
2.5.0 ≤
𝑥
≤ 2.5.0p8
CNA
checkmkcheckmk
2.4.0 ≤
𝑥
≤ 2.4.0p33
CNA
checkmkcheckmk
2.3.0 ≤
𝑥
≤ 2.3.0p48
CNA