CVE-2026-7485 PUBLISHED

Frozen BI aggregations leak host and service names to unauthorized users

Assigner: Checkmk
Reserved: 30.04.2026 Published: 20.08.2026 Updated: 20.08.2026

Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allows an authenticated user with restricted host and service visibility to learn the names and the existence of hosts and services they are not authorized to see.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 2.3

Product Status

Vendor Checkmk GmbH
Product Checkmk
Versions Default: unaffected
  • affected from 2.5.0 to 2.5.0p2 (excl.)
  • affected from 2.4.0 to 2.4.0p29 (excl.)
  • affected from 2.3.0 to 2.3.0p47 (excl.)
  • Version 2.2.0 is affected

Credits

  • Marcus Klein (ITeratio GmbH) reporter

References

Problem Types

  • CWE-863: Incorrect Authorization CWE

Impacts

  • CAPEC-180: Exploiting Incorrectly Configured Access Control Security Levels