Description
Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" permission to modify reports owned by other users.
Published: 2026-07-31
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an authorization flaw that permits an authenticated user who does not possess the "Edit foreign Reports" permission to alter reports belonging to other users. This flaw allows attackers to modify critical business data and potentially conceal malicious changes, leading to integrity loss of report information.

Affected Systems

The affected product is Checkmk by Checkmk GmbH. All Checkmk releases below version 2.5.0p10, below 2.4.0p35, below 2.3.0p49, and the legacy 2.2.0 build are vulnerable. Version 2.2.0 is end‑of‑life but may still be in use in some environments.

Risk and Exploitability

With a CVSS score of 5.3, the vulnerability is of moderate severity. The EPSS score of less than 1% indicates a very low probability that it is actively exploited, and it is not listed in the CISA KEV catalog. Nevertheless, exploitation requires only an authenticated session, so any user with legitimate login credentials but lacking proper authorization could abuse the flaw to tamper with reports. The risk is heightened in shared‑user environments where users with minimal privileges often have file‑system or application access.

Generated by OpenCVE AI on August 2, 2026 at 04:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Checkmk to version 2.5.0p10 or later, or apply the vendor’s patch that adds the missing authorization check
  • Adjust user roles so that only administrators or designated report editors have the "Edit foreign Reports" permission
  • Audit existing report configurations to ensure no unauthorized modifications have already occurred

Generated by OpenCVE AI on August 2, 2026 at 04:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 31 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" permission to modify reports owned by other users.
Title Missing Authorization Allows Editing of Foreign Reports
First Time appeared Checkmk
Checkmk checkmk
Weaknesses CWE-862
CPEs cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.2.0:*:*:*:*:*:*:*
Vendors & Products Checkmk
Checkmk checkmk
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Checkmk

Published:

Updated: 2026-07-31T19:50:52.858Z

Reserved: 2026-07-09T10:46:55.072Z

Link: CVE-2026-15227

cve-icon Vulnrichment

Updated: 2026-07-31T19:50:48.208Z

cve-icon NVD

Status : Received

Published: 2026-07-31T13:17:19.593

Modified: 2026-07-31T20:16:48.100

Link: CVE-2026-15227

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T04:30:13Z

Weaknesses