PT-2026-47285 · Checkmk · Checkmk

CVE-2026-7765

·

Published

2026-06-08

·

Updated

2026-06-08

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Checkmk versions prior to 2.5.0p5
Description Incorrect authorization in the User Messages dashboard widget allows an attacker with a valid public dashboard share token to read the personal messages of the dashboard creator. This occurs because the message-fetching endpoints return the issuer's messages instead of the viewer's. The issue can be exploited by sending requests to the underlying endpoint, regardless of whether a User Messages widget is present on the dashboard.
Recommendations Update to version 2.5.0p5.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7765

Affected Products

Checkmk