CVE-2026-15937
Received Received - Intake

Improper Certificate Validation in Checkmk

Vulnerability report for CVE-2026-15937, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: Checkmk GmbH

Description

Improper certificate validation in Checkmk <2.5.0p10 allows a relay and a push agent that share the same UUID to reuse each other's mTLS certificate to authenticate against agent receiver endpoints in either direction, because the endpoints do not verify that the certificate was issued by their own root certificate.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-05
AI Q&A
2026-09-04
EPSS Evaluated
2026-09-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
checkmk checkmk to 2.5.0p10 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper certificate validation in Checkmk versions before 2.5.0p10. A relay and a push agent sharing the same UUID can reuse each other's mutual TLS certificate to authenticate against agent receiver endpoints in either direction. The endpoints fail to verify if the certificate was issued by their own root certificate, allowing unauthorized authentication.

Detection Guidance

Checkmk versions before 2.5.0p10 are vulnerable. Verify your Checkmk version with 'omd version' or check the web interface. Inspect agent receiver endpoints for unexpected certificate reuse by agents with the same UUID as relays.

Impact Analysis

If you run a relay with push agents registered under the same UUID, an attacker could exploit this flaw to authenticate to your agent receiver endpoints using a compromised certificate. This could lead to unauthorized access or data exfiltration, depending on the endpoint's permissions.

Compliance Impact

This vulnerability could violate compliance requirements that mandate strict access controls and data protection, such as GDPR's integrity and confidentiality principles or HIPAA's safeguards for protected health information. Unauthorized access risks data breaches, leading to potential legal and financial penalties.

Mitigation Strategies

Upgrade Checkmk to version 2.5.0p10 or later. No manual configuration changes are required as the fix is included in the patch. Ensure all agents and relays use unique UUIDs to prevent certificate confusion.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15937. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart