PT-2026-47285 · Checkmk · Checkmk
CVE-2026-7765
·
Published
2026-06-08
·
Updated
2026-06-08
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Checkmk versions prior to 2.5.0p5
Description
Incorrect authorization in the User Messages dashboard widget allows an attacker with a valid public dashboard share token to read the personal messages of the dashboard creator. This occurs because the message-fetching endpoints return the issuer's messages instead of the viewer's. The issue can be exploited by sending requests to the underlying endpoint, regardless of whether a User Messages widget is present on the dashboard.
Recommendations
Update to version 2.5.0p5.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Checkmk