PT-2026-79357 · Checkmk · Checkmk Cloud+2
CVE-2026-15576
·
Published
2026-08-21
·
Updated
2026-08-21
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Checkmk Cloud versions prior to 2.5.0p10
Checkmk Ultimate versions prior to 2.5.0p10
Checkmk Ultimate MT versions prior to 2.5.0p10
Description
Improper authentication in the agent receiver allows an unauthenticated remote attacker to bypass mutual TLS (mTLS) client certificate verification of relay endpoints. This is achieved by supplying a fixed placeholder identity in the request URL, which may lead to a limited impact on integrity and availability. Mutual TLS is a security process where both the client and server verify each other's digital certificates to ensure a secure connection.
Recommendations
Update Checkmk Cloud to version 2.5.0p10 or later.
Update Checkmk Ultimate to version 2.5.0p10 or later.
Update Checkmk Ultimate MT to version 2.5.0p10 or later.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Checkmk Cloud
Checkmk Ultimate
Checkmk Ultimate Mt