Junglewise Threat Intelligence

CVE-2026-15227: Checkmk missing authorization in reporting component

CVE-2026-15227 · Severity: info · CVSS 5.3 · Published 2026-07-31

Executive brief

Checkmk, an IT infrastructure monitoring platform, contains a security flaw that allows users to modify reports they do not own. Even if a user lacks the specific 'Edit foreign Reports' permission, they can still change reports created by other staff members. This could lead to unauthorized changes in monitoring data presentation or the disruption of reporting workflows. Organizations should update to the latest patched versions to ensure proper access controls are enforced.

Technical details

A missing authorization check (CWE-862) in the reporting component of Checkmk allows authenticated users to bypass intended access controls. Specifically, users who lack the 'Edit foreign Reports' permission can still modify reports belonging to other users. The vulnerability is reachable over the network by any user with basic authenticated access to the Checkmk interface. This issue affects Enterprise editions across several major versions. Patches have been released in versions 2.5.0p10, 2.4.0p35, and 2.3.0p49.

Affected products

  • Checkmk GmbH Checkmk < 2.5.0p10, < 2.4.0p35, < 2.3.0p49, 2.2.0 (EOL)

Timeline

  • 2026-07-09: patched: Fix released in multiple versions via Werk #20003
  • 2026-07-31: disclosed: CVE published to NVD

References