Junglewise Threat Intelligence

CVE-2026-15576: Checkmk agent receiver mTLS authentication bypass

CVE-2026-15576 · Severity: info · CVSS 6.9 · Published 2026-08-21

Vendors: Checkmk.

Executive brief

Checkmk's agent receiver component is used to securely receive monitoring data from remote agents and relays. An attacker can bypass mutual TLS certificate verification by supplying a fixed placeholder value in the request URL, allowing unauthenticated access to relay endpoints without presenting a valid client certificate. This affects only Cloud, Ultimate, and Ultimate MT editions.

Technical details

The vulnerability is an improper authentication issue in Checkmk's agent receiver where mTLS-protected endpoints accepted requests without a valid client certificate. When no certificate was provided, the system injected a fixed placeholder identity that could be reused by an attacker in the request URL to bypass mutual TLS verification. The attacker must have network access to the agent receiver endpoints and supply the known placeholder value as the identity parameter. This affects relay endpoints specifically, where an attacker could impersonate a relay without authentication. The fix (released in version 2.5.0p10 and 3.0.0b1) now rejects any mTLS-protected endpoint request that lacks a verified client certificate and blocks client-supplied identity headers.

Affected products

  • Checkmk Checkmk Cloud <2.5.0p10
  • Checkmk Checkmk Ultimate <2.5.0p10
  • Checkmk Checkmk Ultimate MT <2.5.0p10

Timeline

  • 2026-08-21: disclosed: Public disclosure via NVD
  • 2026-07-16: patched: Fixed in Checkmk 2.5.0p10 and 3.0.0b1

References

Related threats