CVE-2026-15227: Checkmk GmbH Checkmk

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" permission to modify reports owned by other users.

Affected products

  • Checkmk GmbH Checkmk: from 2.5.0, before 2.5.0p10 (fixed in 2.5.0p10); from 2.4.0, before 2.4.0p35 (fixed in 2.4.0p35); from 2.3.0, before 2.3.0p49 (fixed in 2.3.0p49); version 2.2.0 only

Published 2026-07-31. Last modified 2026-09-03.