CVE-2026-15227: Missing Authorization Allows Editing of Foreign Reports
Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" permission to modify reports owned by other users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15227?
The severity of CVE-2026-15227 is classified as medium with a CVSS score of 5.3.
How do I fix CVE-2026-15227?
To remediate CVE-2026-15227, upgrade to Checkmk versions 2.5.0p10 or later, 2.4.0p35 or later, or 2.3.0p49 or later.
What does CVE-2026-15227 expose users to?
CVE-2026-15227 exposes users to unauthorized modification of reports owned by other users due to missing authorization.
Which versions of Checkmk are affected by CVE-2026-15227?
Versions of Checkmk affected by CVE-2026-15227 include Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL).
Who can exploit CVE-2026-15227?
Authenticated users lacking the 'Edit foreign Reports' permission can exploit CVE-2026-15227 to modify reports owned by others.