PT-2026-85434 · Checkmk · Checkmk
CVE-2026-15937
·
Published
2026-09-04
·
Updated
2026-09-04
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Checkmk versions prior to 2.5.0p10
Description
Improper certificate validation occurs when a relay and a push agent share the same UUID. This allows them to reuse each other's mTLS (mutual Transport Layer Security, a process where both parties authenticate each other) certificates to authenticate against agent receiver endpoints in either direction. The issue arises because the endpoints fail to verify that the certificate was issued by their own root certificate.
Recommendations
Update to version 2.5.0p10 or later.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Checkmk