CVE-2026-7765

Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creator's messages rather than the viewer's, allowing an attacker who knows a valid public dashboard share token to read the issuer's personal messages by sending requests to the underlying endpoint, even without a User Messages widget present.
References
Link Resource
https://checkmk.com/werk/19815 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:checkmk:checkmk:2.5.0:-:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:b1:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:b2:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:b3:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:p1:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:p2:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:p3:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:p4:*:*:*:*:*:*

History

09 Jun 2026, 14:49

Type Values Removed Values Added
First Time Checkmk checkmk
Checkmk
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CPE cpe:2.3:a:checkmk:checkmk:2.5.0:p4:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:b3:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:-:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:p2:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:p3:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:b2:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:p1:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:b1:*:*:*:*:*:*
References () https://checkmk.com/werk/19815 - () https://checkmk.com/werk/19815 - Vendor Advisory

08 Jun 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-08 13:16

Updated : 2026-06-09 14:49


NVD link : CVE-2026-7765

Mitre link : CVE-2026-7765

CVE.ORG link : CVE-2026-7765


JSON object : View

Products Affected

checkmk

  • checkmk
CWE
CWE-863

Incorrect Authorization