Junglewise Threat Intelligence

CVE-2026-8593: Checkmk improper permission enforcement in Business Intelligence API

CVE-2026-8593 · Severity: info · CVSS 5.3 · Published 2026-07-21

Technologies: Checkmk GmbH Checkmk.

Executive brief

Checkmk is an IT infrastructure monitoring platform used to track the health of servers and networks. A security flaw in its Business Intelligence (BI) component allows users with limited access to view or modify monitoring rules they should not be able to reach. This could lead to unauthorized changes in how business-critical services are monitored or the deletion of important configuration data.

Technical details

A missing authorization check (CWE-862) exists in the Checkmk REST API regarding Business Intelligence (BI) packs. Specifically, the API failed to respect pack-level permissions, allowing authenticated users with general BI access to view, modify, or delete rules within packs they were not authorized to manage. An attacker requires network access to the API and low-level user privileges ('Business Intelligence rules and aggregations' and 'Make changes, perform actions' permissions) to exploit this. The vulnerability is addressed in versions 2.5.0p9, 2.4.0p34, and 2.3.0p49.

Affected products

  • Checkmk GmbH Checkmk 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, 2.2.0 (EOL)

Timeline

  • 2026-05-21: advisory: Vendor advisory Werk #16918 published
  • 2026-07-21: disclosed: CVE published to NVD

References