Improper Authentication in Checkmk Agent Receiver
CVE-2026-15576

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-15576?

The agent receiver in Checkmk prior to version 2.5.0p10 exhibits improper authentication, enabling unauthenticated remote attackers to circumvent mutual TLS client certificate verification. This vulnerability is particularly concerning for users of the Cloud, Ultimate, and Ultimate MT editions, as it exposes relay endpoints to potential attacks. By exploiting this flaw, attackers could manipulate the authentication process using a fixed placeholder identity in request URLs, which compromises the integrity and availability of the affected systems.

Affected Version(s)

Checkmk 2.5.0 < 2.5.0p10

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

PS Positive Security GmbH
.