CVE-2026-24096: Insufficient permission validation on multiple REST API Quick Setup endpoints
Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5.0b2 and 2.4.0 before version 2.4.0p25 allows low-privileged users to perform unauthorized actions or obtain sensitive information
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24096?
CVE-2026-24096 is considered a critical vulnerability due to its potential to allow low-privileged users to perform unauthorized actions.
How do I fix CVE-2026-24096?
To mitigate CVE-2026-24096, it is recommended to upgrade Checkmk to version 2.5.0b2 or later, or 2.4.0p25 or later.
What are the affected versions for CVE-2026-24096?
CVE-2026-24096 affects Checkmk versions prior to 2.5.0b2 and 2.4.0 versions before 2.4.0p25.
What actions can low-privileged users perform due to CVE-2026-24096?
Due to CVE-2026-24096, low-privileged users can perform unauthorized actions across multiple REST API Quick Setup endpoints.
Is there a workaround for CVE-2026-24096?
There is no official workaround for CVE-2026-24096, and the best course of action is to apply the appropriate updates as soon as possible.