CVE-2026-17548: Checkmk GmbH Checkmk

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50 and all 2.2.0 versions allows an authenticated user who knows the ID of a background job to view that job's status and results.

Affected products

  • Checkmk GmbH Checkmk: from 2.5.0, before 2.5.0p12 (fixed in 2.5.0p12); from 2.4.0, before 2.4.0p36 (fixed in 2.4.0p36); from 2.3.0, before 2.3.0p50 (fixed in 2.3.0p50); version 2.2.0 only

Published 2026-08-25. Last modified 2026-08-26.