CVE-2026-15576
Received Received - Intake

Improper Authentication Bypass in Checkmk Agent Receiver

Vulnerability report for CVE-2026-15576, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-21

Last updated on: 2026-08-21

Assigner: Checkmk GmbH

Description

Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass mutual TLS client certificate verification of relay endpoints by supplying a fixed placeholder identity in the request URL, resulting in limited impact on integrity and availability. Only the Cloud, Ultimate and Ultimate MT editions are affected, as other editions do not expose relay endpoints.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-21
Last Modified
2026-08-21
Generated
2026-08-21
AI Q&A
2026-08-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
checkmk checkmk 2.5.0p10

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-15576 is an improper authentication flaw in Checkmk's agent receiver component. It allows unauthenticated remote attackers to bypass mutual TLS (mTLS) client certificate verification by using a fixed placeholder identity in the request URL. This bypasses security checks for relay endpoints, enabling unauthorized access. The issue affects only the Cloud, Ultimate, and Ultimate MT editions of Checkmk versions before 2.5.0p10.

Detection Guidance

Check if your Checkmk instance is running a vulnerable version (2.5.0p10) in the Ultimate, Cloud, or Ultimate MT editions. Verify if relay endpoints are exposed by inspecting the agent receiver logs for requests without valid client certificates or placeholder identity headers.

Impact Analysis

This vulnerability allows attackers to bypass authentication and gain unauthorized access to relay endpoints in Checkmk. While the impact on integrity and availability is limited, it could lead to unauthorized data access or manipulation. Only systems running Checkmk versions before 2.5.0p10 in the affected editions are vulnerable.

Compliance Impact

The vulnerability allows unauthorized access to relay endpoints due to improper authentication, which could lead to data integrity or availability issues. This may impact compliance with standards like GDPR or HIPAA if sensitive data is exposed or altered. The limited impact on integrity and availability suggests minimal direct compliance risk, but unauthorized access could still pose indirect risks depending on data handling.

Mitigation Strategies

Upgrade Checkmk to version 2.5.0p10 or later. Ensure all relay endpoints require valid client certificates and reject requests with placeholder identities. No reconfiguration is needed for legitimate agents or relays.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15576. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart