Executive brief
Checkmk is a popular open-source monitoring and alerting platform. The vulnerability allows an authenticated user to view the status and results of background jobs if they know the job's ID, bypassing authorization checks. While the affected background jobs may contain sensitive monitoring data, the vendor states no sensitive data was observed during testing, making this a low-impact information disclosure risk.
Technical details
The vulnerability is a missing authorization check in Checkmk's background job viewing functionality. An authenticated user who obtains the ID of a background job—either through guessing (for predictable jobs like autodiscovery) or from other means—can access the job's status and results without proper permission validation. The vulnerability requires network access and valid authentication credentials. While background jobs like "activate changes" use random UUIDs making exploitation unlikely, others like "autodiscovery" are more discoverable. The vendor did not identify confirmed sensitive data exposure in testing, but job results could potentially contain system configuration or monitoring details. Patches are available in Checkmk 2.5.0p12, 2.4.0p36, 2.3.0p50, and 3.0.0b1 or later.
Affected products
- Checkmk Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50, all 2.2.0 versions
Timeline
- 2026-08-25: disclosed
- 2026-08-05: patched: Patches released for versions 2.5.0p12, 2.4.0p36, 2.3.0p50, and 3.0.0b1