5.3

CVE-2026-7765

User Messages widget leaked issuer messages on shared dashboards

Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creator's messages rather than the viewer's, allowing an attacker who knows a valid public dashboard share token to read the issuer's personal messages by sending requests to the underlying endpoint, even without a User Messages widget present.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Checkmk ≫ Checkmk Version 2.5.0 Update -
Checkmk ≫ Checkmk Version 2.5.0 Update b1
Checkmk ≫ Checkmk Version 2.5.0 Update b2
Checkmk ≫ Checkmk Version 2.5.0 Update b3
Checkmk ≫ Checkmk Version 2.5.0 Update p1
Checkmk ≫ Checkmk Version 2.5.0 Update p2
Checkmk ≫ Checkmk Version 2.5.0 Update p3
Checkmk ≫ Checkmk Version 2.5.0 Update p4
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.084
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
security@checkmk.com 6.3 0 0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.