Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allows an authenticated user with restricted host and service visibility to learn the names and the existence of hosts and services they are not authorized to see.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://checkmk.com/werk/16917 |
|
History
Thu, 20 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allows an authenticated user with restricted host and service visibility to learn the names and the existence of hosts and services they are not authorized to see. | |
| Title | Frozen BI aggregations leak host and service names to unauthorized users | |
| First Time appeared |
Checkmk
Checkmk checkmk |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Checkmk
Checkmk checkmk |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Checkmk
Published:
Updated: 2026-08-20T12:12:52.811Z
Reserved: 2026-04-30T08:05:18.277Z
Link: CVE-2026-7485
No data.
Status : Received
Published: 2026-08-20T13:19:07.817
Modified: 2026-08-20T13:19:07.817
Link: CVE-2026-7485
No data.
OpenCVE Enrichment
Updated: 2026-08-20T16:30:04Z
Weaknesses