Improper Certificate Validation in Checkmk by Tribe29
CVE-2026-15937

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-15937?

An improper certificate validation vulnerability in Checkmk prior to version 2.5.0p10 allows a relay and push agent sharing the same UUID to misuse each other's mTLS certificate for authenticating against agent receiver endpoints. This occurs because the endpoints fail to verify the certificate's issuance from the correct root certificate, potentially exposing the system to unauthorized access and manipulation.

Affected Version(s)

Checkmk 2.5.0 < 2.5.0p10

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

PS Positive Security GmbH
.