CVE Database
/

CVE-2025-64997

Back to search

CVE-2025-64997

Published: Dec 18, 2025

Modified: Dec 18, 2025

PUBLISHED

Description

Insufficient permission validation in Checkmk versions prior to 2.4.0p17 and 2.3.0p42 allow low-privileged users to view agent information via the REST API, which could lead to information disclosure.

VendorProductVersions

Checkmk GmbH

Checkmk

affected
2.4.0 - < 2.4.0p17
affected
2.3.0 - < 2.3.0p42

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now