CVE-2026-15576
- EPSS -
- Veröffentlicht 21.08.2026 11:10:00
- Zuletzt bearbeitet 21.08.2026 12:16:23
Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass mutual TLS client certificate verification of relay endpoints by supplying a fixed placeholder identity in the request URL, resulti...
CVE-2026-7485
- EPSS -
- Veröffentlicht 20.08.2026 12:12:52
- Zuletzt bearbeitet 20.08.2026 13:19:07
Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allows an authenticated user with restricted host and service visibility to learn the names and the existence of hosts and services th...
CVE-2026-15227
- EPSS 0.21%
- Veröffentlicht 31.07.2026 12:21:58
- Zuletzt bearbeitet 31.07.2026 20:16:48
Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" permission to modify reports owned by other users.
CVE-2026-8593
- EPSS 0.21%
- Veröffentlicht 21.07.2026 07:20:35
- Zuletzt bearbeitet 22.07.2026 20:51:36
Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to view and modify BI packs and rules
CVE-2026-14852
- EPSS 0.22%
- Veröffentlicht 14.07.2026 09:26:28
- Zuletzt bearbeitet 29.07.2026 20:17:01
Privilege escalation in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows a local unprivileged user to execute arbitrary commands as root by starting a process crafted to look like a SAP HANA ...
CVE-2026-9549
- EPSS 0.14%
- Veröffentlicht 08.06.2026 12:07:12
- Zuletzt bearbeitet 23.07.2026 07:10:00
Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can configure active or custom checks to inject malicious HTML or JavaScript into c...
CVE-2026-8833
- EPSS 0.14%
- Veröffentlicht 08.06.2026 12:06:51
- Zuletzt bearbeitet 23.07.2026 07:10:00
Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an authenticated user to bypass URL validation and inject malicious URLs such as javascript: UR...
CVE-2026-8078
- EPSS 0.14%
- Veröffentlicht 08.06.2026 12:06:36
- Zuletzt bearbeitet 23.07.2026 07:10:00
Stored cross-site scripting in the global settings change log in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can change global settings to store malicious HTML or JavaScript in changelog messages that ex...
CVE-2026-7765
- EPSS 0.19%
- Veröffentlicht 08.06.2026 12:06:02
- Zuletzt bearbeitet 23.07.2026 07:10:00
Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creator's messages rather than the viewer's, allowing an attacker who knows a valid public dashboard share...
CVE-2026-7186
- EPSS 0.14%
- Veröffentlicht 08.06.2026 12:05:28
- Zuletzt bearbeitet 23.07.2026 07:10:00
Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows a user with dashboard editing permissions to store a URL with a dangerous URI scheme such as javascript: that executes sc...