Checkmk Gmbh · Checkmk · CVE-2026-7485
**Name of the Vulnerable Software and Affected Versions**
Checkmk versions prior to 2.5.0p2
Checkmk versions prior to 2.4.0p29
Checkmk versions prior to 2.3.0p47
Checkmk versions 2.2.0 through 2.2.x
**Description**
Incorrect authorization in frozen BI aggregations allows an authenticated user with restricted host and service visibility to discover the names and existence of hosts and services they are not authorized to access.
**Recommendations**
Update to version 2.5.0p2 or later.
Update to version 2.4.0p29 or later.
Update to version 2.3.0p47 or later.
Update to a version newer than 2.2.x.