CVE-2026-8593 PUBLISHED

Fix Business Intelligence API Pack permission

Assigner: Checkmk
Reserved: 14.05.2026 Published: 21.07.2026 Updated: 21.07.2026

Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to view and modify BI packs and rules

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor Checkmk GmbH
Product Checkmk
Versions Default: unaffected
  • affected from 2.5.0 to 2.5.0p9 (excl.)
  • affected from 2.4.0 to 2.4.0p34 (excl.)
  • affected from 2.3.0 to 2.3.0p49 (excl.)

References

Problem Types

  • CWE-862: Missing Authorization CWE

Impacts

  • CAPEC-180: Exploiting Incorrectly Configured Access Control Security Levels