Description
Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creator's messages rather than the viewer's, allowing an attacker who knows a valid public dashboard share token to read the issuer's personal messages by sending requests to the underlying endpoint, even without a User Messages widget present.
Published: 2026-06-08
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from incorrect authorization in the User Messages dashboard widget in Checkmk versions below 2.5.0p5. Affected endpoints that fetch messages return the creator's personal messages instead of those of the viewer, enabling an attacker to obtain sensitive communication intended only for the dashboard owner. This flaw results in the disclosure of private user messages, violating confidentiality and potentially exposing personal data. The flaw is categorized as a Missing Authorization issue, specifically CWE-863.

Affected Systems

The flaw targets Checkmk by Checkmk GmbH, specifically all Checkmk Checkmk releases earlier than version 2.5.0p5. Systems that run a shared dashboard with public sharing enabled and contain the User Messages widget are susceptible. Any version in the vulnerable range, regardless of platform, is affected.

Risk and Exploitability

The CVSS score is 6.3, indicating a moderate severity. The EPSS score is not available, so exploitation likelihood cannot be quantified, but the flaw is publicly documented and can be leveraged if an attacker obtains a valid public dashboard share token. The vulnerability is not listed in the CISA KEV, though organizations should still consider patching immediately. An attacker can simply send requests to the underlying message endpoint using the known token, gaining the creator’s messages. The absence of an authorization check makes the exploitation straightforward once the token is known.

Generated by OpenCVE AI on June 8, 2026 at 15:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Checkmk to version 2.5.0p5 or later to address the authorization flaw
  • Revoke or rotate any shared dashboard tokens that may have been exposed
  • Restrict public sharing of dashboards containing the User Messages widget or disable the widget from public dashboards

Generated by OpenCVE AI on June 8, 2026 at 15:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 09 Jun 2026 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:checkmk:checkmk:2.5.0:-:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:b1:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:b2:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:b3:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:p1:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:p2:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:p3:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:p4:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Mon, 08 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 08 Jun 2026 13:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creator's messages rather than the viewer's, allowing an attacker who knows a valid public dashboard share token to read the issuer's personal messages by sending requests to the underlying endpoint, even without a User Messages widget present.
Title User Messages widget leaked issuer messages on shared dashboards
First Time appeared Checkmk
Checkmk checkmk
Weaknesses CWE-863
CPEs cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*
Vendors & Products Checkmk
Checkmk checkmk
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Checkmk

Published:

Updated: 2026-06-08T13:04:57.779Z

Reserved: 2026-05-04T09:31:55.031Z

Link: CVE-2026-7765

cve-icon Vulnrichment

Updated: 2026-06-08T13:04:54.602Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-08T13:16:33.627

Modified: 2026-06-09T14:49:38.500

Link: CVE-2026-7765

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-08T15:15:26Z

Weaknesses