PT-2026-79357 · Checkmk · Checkmk Cloud+2

CVE-2026-15576

·

Published

2026-08-21

·

Updated

2026-08-21

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Checkmk Cloud versions prior to 2.5.0p10 Checkmk Ultimate versions prior to 2.5.0p10 Checkmk Ultimate MT versions prior to 2.5.0p10
Description Improper authentication in the agent receiver allows an unauthenticated remote attacker to bypass mutual TLS (mTLS) client certificate verification of relay endpoints. This is achieved by supplying a fixed placeholder identity in the request URL, which may lead to a limited impact on integrity and availability. Mutual TLS is a security process where both the client and server verify each other's digital certificates to ensure a secure connection.
Recommendations Update Checkmk Cloud to version 2.5.0p10 or later. Update Checkmk Ultimate to version 2.5.0p10 or later. Update Checkmk Ultimate MT to version 2.5.0p10 or later.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15576

Affected Products

Checkmk Cloud
Checkmk Ultimate
Checkmk Ultimate Mt