CVE-2026-17548: Missing authorization for viewing background jobs
Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50 and all 2.2.0 versions allows an authenticated user who knows the ID of a background job to view that job's status and results.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Checkmkto a version that resolves this vulnerability.Fixed in 2.5.0p12 - Upgrade
Upgrade
Checkmkto a version that resolves this vulnerability.Fixed in 2.4.0p36 - Upgrade
Upgrade
Checkmkto a version that resolves this vulnerability.Fixed in 2.3.0p50 - Upgrade
Upgrade
Checkmkto a version that resolves this vulnerability.Fixed in 2.2.0
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated to Checkmk and know the ID of a background job. No user interaction is required.
What information could be exposed?
The attacker can view the status and results of background jobs. The available data does not indicate that the attacker can modify jobs or affect availability.
Which releases are affected?
Affected releases are Checkmk versions earlier than 2.5.0p12, earlier than 2.4.0p36, earlier than 2.3.0p50, and all 2.2.0 versions.