← Back

CVE-2026-7765

nvd nist
Published: Jun 8, 2026Modified: Jul 23, 2026

JSON object

Loading...
6.3
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: security@checkmk.com (Secondary)

Description

Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creator's messages rather than the viewer's, allowing an attacker who knows a valid public dashboard share token to read the issuer's personal messages by sending requests to the underlying endpoint, even without a User Messages widget present.

Affected (8)

Products: Checkmk: Checkmk
1 product
Checkmk
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Checkmk
Version 2.5.0
Version 2.5.0 b1
Version 2.5.0 b2
Version 2.5.0 b3
Version 2.5.0 p1
Version 2.5.0 p2
Version 2.5.0 p3
Version 2.5.0 p4

References (1)

Source: security@checkmk.com
Vendor Advisory

Timeline

No history available yet.