CVE-2026-15576: Agent receiver accepts mTLS requests without a client certificate

Published Aug 21, 2026
·
Updated

Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass mutual TLS client certificate verification of relay endpoints by supplying a fixed placeholder identity in the request URL, resulting in limited impact on integrity and availability. Only the Cloud, Ultimate and Ultimate MT editions are affected, as other editions do not expose relay endpoints.

Affected Software

4 affected components
Checkmk Checkmk<2.5.0p10
Checkmk (Cloud)<2.5.0p10
Checkmk (Ultimate)<2.5.0p10
Checkmk (Ultimate MT)<2.5.0p10

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Checkmk to a version that resolves this vulnerability.

    Fixed in 2.5.0p10

Event History

Aug 21, 2026
CVE Published
via MITRE·11:10 AM
Data Sourced
via MITRE·11:10 AM
DescriptionWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Only Checkmk Cloud, Ultimate, and Ultimate MT editions are affected because they expose relay endpoints. Other editions do not expose relay endpoints and are not affected.

2

What does an attacker need to exploit the vulnerability?

An unauthenticated remote attacker must be able to send requests to a relay endpoint and supply a fixed placeholder identity in the request URL. No valid mTLS client certificate is required.

3

Are affected deployments safe if mutual TLS is configured?

No. The flaw bypasses mutual TLS client-certificate verification at the agent receiver for relay endpoints.

4

What is the impact of successful exploitation?

Successful exploitation has limited impact on integrity and availability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203