PT-2026-78995 · Checkmk Gmbh+1 · Checkmk

·

CVE-2026-7485

·

Published

2026-08-20

·

Updated

2026-08-21

CVSS v4.0

2.3

Low

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Checkmk versions prior to 2.5.0p2 Checkmk versions prior to 2.4.0p29 Checkmk versions prior to 2.3.0p47 Checkmk versions 2.2.0 through 2.2.x
Description Incorrect authorization in frozen BI aggregations allows an authenticated user with restricted host and service visibility to discover the names and existence of hosts and services they are not authorized to access.
Recommendations Update to version 2.5.0p2 or later. Update to version 2.4.0p29 or later. Update to version 2.3.0p47 or later. Update to a version newer than 2.2.x.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7485

Affected Products

Checkmk