Insufficient Permissions in Checkmk REST API Affects User Privileges
CVE-2026-24096
5.3MEDIUM
What is CVE-2026-24096?
The vulnerability in Checkmk's REST API arises from a lack of proper permission validation in multiple Quick Setup endpoints. This flaw allows low-privileged users to execute unauthorized actions or access sensitive information, potentially compromising system security. Versions affected include Checkmk 2.5.0 (beta) before 2.5.0b2 and 2.4.0 before 2.4.0p25, highlighting the need for immediate remediation to safeguard against unauthorized data exposure.
Affected Version(s)
Checkmk 2.5.0b1 < 2.5.0b2
Checkmk 2.4.0 < 2.4.0p25
