5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Description
Insufficient permission validation on multiple REST API endpoints in Checkmk 2.2.0, 2.3.0, and 2.4.0 before version 2.4.0p16 allows low-privileged users to perform unauthorized actions or obtain sensitive information
Basic Information
ID
CVE-2025-58121
Source
Checkmk
Published
Nov 18, 2025 at 15:11
Modified
Nov 18, 2025 at 21:34
Affected Product
Vendor
Checkmk GmbH
Product
Checkmk
Version
2.4.0
Affected Versions
Checkmk GmbH Checkmk 2.4.0
Checkmk GmbH Checkmk 2.3.0
Checkmk GmbH Checkmk 2.2.0
Checkmk GmbH Checkmk 2.3.0
Checkmk GmbH Checkmk 2.2.0