Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p21, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows users with the "Use WATO" permission to access the "Analyze configuration" page by directly navigating to its URL, bypassing the intended "Access analyze configuration" permission check. If these users also have the "Make changes, perform actions" permission, they can perform unauthorized actions such as disabling checks or acknowledging results.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://checkmk.com/werk/19032 |
Configurations
No configuration.
History
09 Feb 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-09 16:16
Updated : 2026-02-09 21:55
NVD link : CVE-2026-24095
Mitre link : CVE-2026-24095
CVE.ORG link : CVE-2026-24095
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
