PT-2026-81216 · Checkmk · Checkmk

CVE-2026-17548

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Checkmk versions prior to 2.5.0p12 Checkmk versions prior to 2.4.0p36 Checkmk versions prior to 2.3.0p50 Checkmk versions 2.2.0 through 2.2.x
Description An authorization flaw allows an authenticated user to view the status and results of a background job if they possess the specific job ID.
Recommendations Update to version 2.5.0p12 or later. Update to version 2.4.0p36 or later. Update to version 2.3.0p50 or later. Update to a version newer than 2.2.x.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17548

Affected Products

Checkmk