Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p21, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows users with the "Use WATO" permission to access the "Analyze configuration" page by directly navigating to its URL, bypassing the intended "Access analyze configuration" permission check. If these users also have the "Make changes, perform actions" permission, they can perform unauthorized actions such as disabling checks or acknowledging results.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://checkmk.com/werk/19032 |
|
History
Mon, 09 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Feb 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p21, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows users with the "Use WATO" permission to access the "Analyze configuration" page by directly navigating to its URL, bypassing the intended "Access analyze configuration" permission check. If these users also have the "Make changes, perform actions" permission, they can perform unauthorized actions such as disabling checks or acknowledging results. | |
| Title | Missing Permission Check on Analyze Configuration Page | |
| First Time appeared |
Checkmk
Checkmk checkmk |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Checkmk
Checkmk checkmk |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Checkmk
Published:
Updated: 2026-02-09T15:54:18.156Z
Reserved: 2026-01-21T14:39:24.127Z
Link: CVE-2026-24095
Updated: 2026-02-09T15:54:08.329Z
Status : Received
Published: 2026-02-09T16:16:00.767
Modified: 2026-02-09T16:16:00.767
Link: CVE-2026-24095
No data.
OpenCVE Enrichment
No data.