Junglewise Threat Intelligence

CVE-2026-7485: Checkmk incorrect authorization in frozen BI aggregations

CVE-2026-7485 · Severity: info · CVSS 2.3 · Published 2026-08-20

Technologies: Checkmk. Vendors: Checkmk.

Executive brief

Checkmk is a monitoring and observability platform used by enterprises to track infrastructure health. A flaw in frozen Business Intelligence (BI) aggregations allows authenticated users with restricted access to discover the names and existence of hosts and services they should not be able to see, potentially revealing sensitive infrastructure details to unauthorized personnel.

Technical details

The vulnerability is an authorization bypass in Checkmk's frozen BI aggregation functionality. When restricted users query aggregations, inaccessible hosts or services are returned as "Service/Host not found" instead of being hidden, allowing attackers to infer the existence and names of monitored infrastructure. The flaw requires authentication and affects versions 2.5.0 before p2, 2.4.0 before p29, 2.3.0 before p47, and all 2.2.0 versions (EOL). The fix prevents restricted users from seeing any details about elements they lack authorization to access, while still reporting genuinely missing elements as "not found".

Affected products

  • Checkmk Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, all 2.2.0

Timeline

  • 2026-04-29: disclosed: Fix released in Checkmk 2.5.0p2, 2.4.0p29, 2.3.0p47
  • 2026-08-20: advisory: CVE-2026-7485 published

References

Related threats