CVE-2026-24095: Checkmk GmbH Checkmk
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p21, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows users with the "Use WATO" permission to access the "Analyze configuration" page by directly navigating to its URL, bypassing the intended "Access analyze configuration" permission check. If these users also have the "Make changes, perform actions" permission, they can perform unauthorized actions such as disabling checks or acknowledging results.
Affected products
- Checkmk GmbH Checkmk: from 2.4.0, before 2.4.0p21 (fixed in 2.4.0p21); from 2.3.0, before 2.3.0p43 (fixed in 2.3.0p43); version 2.2.0 only
Published 2026-02-09. Last modified 2026-06-17.