CVE-2025-3506: Checkmk

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Files to be deployed with agents are accessible without authentication in Checkmk 2.1.0, Checkmk 2.2.0, Checkmk 2.3.0 and <Checkmk 2.4.0b6 allows attacker to access files that could contain secrets.

Affected products

  • Checkmk Checkmk: from 2.1.0, up to and including 2.3.0; version 2.4.0 only

Published 2025-05-08. Last modified 2026-06-17.