Description
Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allows an authenticated user with restricted host and service visibility to learn the names and the existence of hosts and services they are not authorized to see.
Published: 2026-08-20
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an incorrect authorization check in frozen Business Intelligence aggregations. It allows an authenticated user who normally has restricted view of certain hosts and services to discover the names and existence of those entities. This breach of confidentiality enables the attacker to build a more complete inventory of the environment for later exploits.

Affected Systems

The flaw exists in Checkmk versions prior to 2.5.0p2, prior to 2.4.0p29, prior to 2.3.0p47, and in all 2.2.0 releases. It affects Checkmk as delivered by Checkmk GmbH, including the open‑source Community Edition and Enterprise releases.

Risk and Exploitability

The CVSS score of 2.3 indicates a low overall impact, yet the information collected could assist in reconnaissance. The exploit requires a valid authenticated session; there is no remote code execution or denial of service. EPSS is not available and the issue is not listed in the CISA KEV catalog, suggesting no known exploits and a low probability of widespread exploitation. The likely attack vector is a legitimate user accessing the Checkmk interface, possibly from a trusted network location.

Generated by OpenCVE AI on August 20, 2026 at 21:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the earliest release that contains the fix— Checkmk release at or beyond 2.5.0p2, 2.4.0p29, 2.3.0p47, or the latest 2.2.x patch level.
  • If an upgrade cannot be applied immediately, disable the frozen BI aggregation feature or remove user permissions to access BI aggregations.
  • Re‑evaluate and tighten role‑based access controls so that only authorized personnel can view host and service names.

Generated by OpenCVE AI on August 20, 2026 at 21:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 26 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allows an authenticated user with restricted host and service visibility to learn the names and the existence of hosts and services they are not authorized to see.
Title Frozen BI aggregations leak host and service names to unauthorized users
First Time appeared Checkmk
Checkmk checkmk
Weaknesses CWE-863
CPEs cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.2.0:*:*:*:*:*:*:*
Vendors & Products Checkmk
Checkmk checkmk
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Checkmk

Published:

Updated: 2026-08-26T14:16:37.692Z

Reserved: 2026-04-30T08:05:18.277Z

Link: CVE-2026-7485

cve-icon Vulnrichment

Updated: 2026-08-20T13:27:26.916Z

cve-icon NVD

Status : Deferred

Published: 2026-08-20T13:19:07.817

Modified: 2026-08-26T18:56:51.417

Link: CVE-2026-7485

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T21:45:05Z

Weaknesses