LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-2859

checkmk · checkmk

Published
CVSS4.3
Severitymedium
WeaknessCWE-204
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Description

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows unauthenticated users to enumerate existing hosts by observing different HTTP response codes in deploy_agent endpoint, which could lead to information disclosure.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-2859

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-2859.