CVE-2026-7485

Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allows an authenticated user with restricted host and service visibility to learn the names and the existence of hosts and services they are not authorized to see.
CVSS

No CVSS.

References
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-20 13:19

Updated : 2026-08-26 18:56


NVD link : CVE-2026-7485

Mitre link : CVE-2026-7485

CVE.ORG link : CVE-2026-7485


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization