CVE-2024-38864: Checkmk

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p23, < 2.2.0p38 and <= 2.1.0p49 (EOL) allows a local attacker to read sensitive data.

Affected products

  • Checkmk Checkmk: before 2.1.0 (fixed in 2.1.0); version 2.1.0 only; version 2.2.0 only; version 2.3.0 only

Published 2024-12-19. Last modified 2026-06-17.