CVE-2026-8593
Received Received - Intake

Improper Permission Enforcement in Checkmk

Vulnerability report for CVE-2026-8593, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-07-21

Assigner: Checkmk GmbH

Description

Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to view and modify BI packs and rules

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-07-21
Generated
2026-07-21
AI Q&A
2026-07-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
checkmk checkmk to 2.5.0p9 (exc)
checkmk checkmk to 2.4.0p34 (exc)
checkmk checkmk to 2.3.0p49 (exc)
checkmk checkmk 2.2.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-8593 is an improper permission enforcement flaw in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL). It allows users without proper permissions to view and modify Business Intelligence (BI) packs and rules.

Detection Guidance

To detect this vulnerability, review Checkmk user permissions for BI rule modifications. Check if users without BI pack access can delete rules via the REST API. Verify if users with 'Business Intelligence rules and aggregations' and 'Make changes, perform actions' permissions can delete rules without proper BI pack customization rights.

Impact Analysis

An attacker with limited permissions could delete BI rules via the REST API, potentially disrupting monitoring and alerting functions. This could lead to incorrect system status reporting or loss of critical monitoring data.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized users to modify or delete BI rules, which may include monitoring configurations for sensitive data. Unauthorized changes could lead to improper data handling or loss of audit trails, violating principles of data integrity and access control required by these regulations.

Mitigation Strategies

Update Checkmk to versions 2.5.0p9, 2.4.0p34, or 2.3.0p49 or later. If updating is not possible, restrict access to BI rule identifiers for users with the mentioned permissions. Ensure only authorized users can customize BI packs before allowing rule deletions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8593. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart