PT-2025-47324 · Checkmk · Checkmk
Published
2025-11-18
·
Updated
2025-11-24
·
CVE-2025-58121
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Checkmk versions 2.2.0, 2.3.0, and 2.4.0 through 2.4.0p15
Description
Improper permission checks on several REST API endpoints in the software permit users with limited privileges to execute actions they should not be authorized to perform or access confidential data. The issue affects multiple ''API endpoints''. Low-privileged users can potentially perform unauthorized actions or obtain sensitive information.
Recommendations
Update to version 2.4.0p16 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Checkmk