PT-2026-85434 · Checkmk · Checkmk

CVE-2026-15937

·

Published

2026-09-04

·

Updated

2026-09-04

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Checkmk versions prior to 2.5.0p10
Description Improper certificate validation occurs when a relay and a push agent share the same UUID. This allows them to reuse each other's mTLS (mutual Transport Layer Security, a process where both parties authenticate each other) certificates to authenticate against agent receiver endpoints in either direction. The issue arises because the endpoints fail to verify that the certificate was issued by their own root certificate.
Recommendations Update to version 2.5.0p10 or later.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15937

Affected Products

Checkmk