CVE-2026-7765

Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creator's messages rather than the viewer's, allowing an attacker who knows a valid public dashboard share token to read the issuer's personal messages by sending requests to the underlying endpoint, even without a User Messages widget present.
References
Link Resource
https://checkmk.com/werk/19815 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:checkmk:checkmk:2.5.0:-:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:b1:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:b2:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:b3:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:p1:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:p2:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:p3:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:p4:*:*:*:*:*:*

History

23 Jul 2026, 07:10

Type Values Removed Values Added
Summary
  • (es) Autorización incorrecta en el widget del panel de control de Mensajes de Usuario en Checkmk <2.5.0p5 provoca que los puntos finales de recuperación de mensajes devuelvan los mensajes del creador del panel de control en lugar de los del espectador, permitiendo a un atacante que conoce un token de compartición de panel de control público válido leer los mensajes personales del emisor enviando solicitudes al punto final subyacente, incluso sin un widget de Mensajes de Usuario presente.

09 Jun 2026, 14:49

Type Values Removed Values Added
First Time Checkmk checkmk
Checkmk
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CPE cpe:2.3:a:checkmk:checkmk:2.5.0:p4:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:b3:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:-:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:p2:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:p3:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:b2:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:p1:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.5.0:b1:*:*:*:*:*:*
References () https://checkmk.com/werk/19815 - () https://checkmk.com/werk/19815 - Vendor Advisory

08 Jun 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-08 13:16

Updated : 2026-07-23 07:10


NVD link : CVE-2026-7765

Mitre link : CVE-2026-7765

CVE.ORG link : CVE-2026-7765


JSON object : View

Products Affected

checkmk

  • checkmk
CWE
CWE-863

Incorrect Authorization