CVE Database
/

CVE-2026-24095

Back to search

CVE-2026-24095

Published: Feb 9, 2026

Modified: Feb 9, 2026

PUBLISHED

Description

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p21, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows users with the "Use WATO" permission to access the "Analyze configuration" page by directly navigating to its URL, bypassing the intended "Access analyze configuration" permission check. If these users also have the "Make changes, perform actions" permission, they can perform unauthorized actions such as disabling checks or acknowledging results.

VendorProductVersions

Checkmk GmbH

Checkmk

affected
2.4.0 - < 2.4.0p21
affected
2.3.0 - < 2.3.0p43
affected
2.2.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now