Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allows an authenticated user with restricted host and service visibility to learn the names and the existence of hosts and services they are not authorized to see.

Project Subscriptions

Vendors Products
Checkmk Subscribe
Checkmk Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

Thu, 20 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allows an authenticated user with restricted host and service visibility to learn the names and the existence of hosts and services they are not authorized to see.
Title Frozen BI aggregations leak host and service names to unauthorized users
First Time appeared Checkmk
Checkmk checkmk
Weaknesses CWE-863
CPEs cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.2.0:*:*:*:*:*:*:*
Vendors & Products Checkmk
Checkmk checkmk
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Checkmk

Published:

Updated: 2026-08-20T12:12:52.811Z

Reserved: 2026-04-30T08:05:18.277Z

Link: CVE-2026-7485

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-20T13:19:07.817

Modified: 2026-08-20T13:19:07.817

Link: CVE-2026-7485

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T16:30:04Z

Weaknesses