Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-58122


Insufficient permission validation in Checkmk 2.4.0 before version 2.4.0p16 allows low-privileged users to modify notification parameters via the REST API, which could lead to unauthorized actions or information disclosure.


Published

2025-11-18T16:15:44.930

Last Modified

2025-11-24T13:58:28.350

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-280

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application checkmk checkmk 2.4.0 Yes
Application checkmk checkmk 2.4.0 Yes
Application checkmk checkmk 2.4.0 Yes
Application checkmk checkmk 2.4.0 Yes
Application checkmk checkmk 2.4.0 Yes
Application checkmk checkmk 2.4.0 Yes
Application checkmk checkmk 2.4.0 Yes
Application checkmk checkmk 2.4.0 Yes
Application checkmk checkmk 2.4.0 Yes
Application checkmk checkmk 2.4.0 Yes
Application checkmk checkmk 2.4.0 Yes
Application checkmk checkmk 2.4.0 Yes
Application checkmk checkmk 2.4.0 Yes
Application checkmk checkmk 2.4.0 Yes
Application checkmk checkmk 2.4.0 Yes
Application checkmk checkmk 2.4.0 Yes
Application checkmk checkmk 2.4.0 Yes
Application checkmk checkmk 2.4.0 Yes
Application checkmk checkmk 2.4.0 Yes
Application checkmk checkmk 2.4.0 Yes
Application checkmk checkmk 2.4.0 Yes
Application checkmk checkmk 2.4.0 Yes

References