Description
Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to view and modify BI packs and rules
Published: 2026-07-21
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper permission enforcement flaw that allows users who are not granted Business Intelligence (BI) pack read or write rights to view and modify those packs and the rules associated with them. This means an attacker with any authenticated session can obtain data and make changes that should have been restricted, compromising confidentiality and integrity of BI content. The weakness is classified as CWE‑862, Permission‑Check Failure.

Affected Systems

Checkmk GmbH’s Checkmk product is affected in releases prior to 2.5.0p9, 2.4.0p34, 2.3.0p49, and the end‑of‑life 2.2.0. Users operating those versions should verify whether their installation falls within the stated version ranges.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1 % suggests that the vulnerability is currently unlikely to be widely exploited. The flaw is not listed in CISA’s KEV catalog. An attacker would need an authenticated access to the Checkmk instance and could exploit the permission bypass to read or modify BI packs and rules, affecting system integrity and potentially providing a foothold for further attacks.

Generated by OpenCVE AI on August 1, 2026 at 07:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Checkmk to a fixed release: 2.5.0p9 or newer, 2.4.0p34 or newer, 2.3.0p49 or newer, or discontinue use of the end‑of‑life 2.2.0 version.
  • Apply the principle of least privilege by removing default BI pack permissions from all users and granting explicit edit rights only to trusted accounts.
  • Continuously monitor BI pack access and modification logs to detect any unauthorized activity.

Generated by OpenCVE AI on August 1, 2026 at 07:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 21 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Description Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to view and modify BI packs and rules
Title Fix Business Intelligence API Pack permission
First Time appeared Checkmk
Checkmk checkmk
Weaknesses CWE-862
CPEs cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*
Vendors & Products Checkmk
Checkmk checkmk
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Checkmk

Published:

Updated: 2026-07-21T12:16:52.202Z

Reserved: 2026-05-14T11:33:18.585Z

Link: CVE-2026-8593

cve-icon Vulnrichment

Updated: 2026-07-21T12:16:48.738Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T07:15:03Z

Weaknesses