Impact
The vulnerability is an authorization flaw that permits an authenticated user who does not possess the "Edit foreign Reports" permission to alter reports belonging to other users. This flaw allows attackers to modify critical business data and potentially conceal malicious changes, leading to integrity loss of report information.
Affected Systems
The affected product is Checkmk by Checkmk GmbH. All Checkmk releases below version 2.5.0p10, below 2.4.0p35, below 2.3.0p49, and the legacy 2.2.0 build are vulnerable. Version 2.2.0 is end‑of‑life but may still be in use in some environments.
Risk and Exploitability
With a CVSS score of 5.3, the vulnerability is of moderate severity. The EPSS score of less than 1% indicates a very low probability that it is actively exploited, and it is not listed in the CISA KEV catalog. Nevertheless, exploitation requires only an authenticated session, so any user with legitimate login credentials but lacking proper authorization could abuse the flaw to tamper with reports. The risk is heightened in shared‑user environments where users with minimal privileges often have file‑system or application access.
OpenCVE Enrichment