Junglewise Threat Intelligence

CVE-2026-17548: Checkmk missing authorization in background job viewing

CVE-2026-17548 · Severity: info · CVSS 5.3 · Published 2026-08-25

Technologies: Checkmk. Vendors: Checkmk.

Executive brief

Checkmk is a popular open-source monitoring and alerting platform. The vulnerability allows an authenticated user to view the status and results of background jobs if they know the job's ID, bypassing authorization checks. While the affected background jobs may contain sensitive monitoring data, the vendor states no sensitive data was observed during testing, making this a low-impact information disclosure risk.

Technical details

The vulnerability is a missing authorization check in Checkmk's background job viewing functionality. An authenticated user who obtains the ID of a background job—either through guessing (for predictable jobs like autodiscovery) or from other means—can access the job's status and results without proper permission validation. The vulnerability requires network access and valid authentication credentials. While background jobs like "activate changes" use random UUIDs making exploitation unlikely, others like "autodiscovery" are more discoverable. The vendor did not identify confirmed sensitive data exposure in testing, but job results could potentially contain system configuration or monitoring details. Patches are available in Checkmk 2.5.0p12, 2.4.0p36, 2.3.0p50, and 3.0.0b1 or later.

Affected products

  • Checkmk Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50, all 2.2.0 versions

Timeline

  • 2026-08-25: disclosed
  • 2026-08-05: patched: Patches released for versions 2.5.0p12, 2.4.0p36, 2.3.0p50, and 3.0.0b1

References

Related threats