Improper Permission Enforcement in Checkmk by Tribe29
CVE-2026-8593

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-8593?

A flaw in Checkmk versions prior to 2.5.0p9, 2.4.0p34, 2.3.0p49, and the End of Life 2.2.0 version permits users lacking proper permissions to access and manipulate Business Intelligence (BI) packs and rules. This vulnerability can potentially lead to unauthorized data exposure and modification, posing a significant risk to system integrity and security.

Affected Version(s)

Checkmk 2.5.0 < 2.5.0p9

Checkmk 2.4.0 < 2.4.0p34

Checkmk 2.3.0 < 2.3.0p49

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.