CVE-2025-32915: Checkmk
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42 and <= 2.1.0p49 (EOL). This allows a local attacker to read sensitive data.
Affected products
- Checkmk Checkmk: version 2.1.0 only; version 2.2.0 only; version 2.3.0 only; version 2.4.0 only
Published 2025-05-22. Last modified 2026-06-17.