Improper Certificate Validation in Checkmk by Tribe29
CVE-2026-15937
5.3MEDIUM
What is CVE-2026-15937?
An improper certificate validation vulnerability in Checkmk prior to version 2.5.0p10 allows a relay and push agent sharing the same UUID to misuse each other's mTLS certificate for authenticating against agent receiver endpoints. This occurs because the endpoints fail to verify the certificate's issuance from the correct root certificate, potentially exposing the system to unauthorized access and manipulation.
Affected Version(s)
Checkmk 2.5.0 < 2.5.0p10
