Impact
The vulnerability is an improper permission enforcement flaw that allows users who are not granted Business Intelligence (BI) pack read or write rights to view and modify those packs and the rules associated with them. This means an attacker with any authenticated session can obtain data and make changes that should have been restricted, compromising confidentiality and integrity of BI content. The weakness is classified as CWE‑862, Permission‑Check Failure.
Affected Systems
Checkmk GmbH’s Checkmk product is affected in releases prior to 2.5.0p9, 2.4.0p34, 2.3.0p49, and the end‑of‑life 2.2.0. Users operating those versions should verify whether their installation falls within the stated version ranges.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1 % suggests that the vulnerability is currently unlikely to be widely exploited. The flaw is not listed in CISA’s KEV catalog. An attacker would need an authenticated access to the Checkmk instance and could exploit the permission bypass to read or modify BI packs and rules, affecting system integrity and potentially providing a foothold for further attacks.
OpenCVE Enrichment