CVE-2026-24097: Authenticated Host Enumeration via Observable Response Discrepancy on Agent Register Existing Endpoint
Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows authenticated users to enumerate existing hosts by observing different HTTP response codes in agent-receiver/registerexisting endpoint, which could lead to information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24097?
CVE-2026-24097 is considered a medium severity vulnerability due to improper permission enforcement that allows authenticated users to enumerate existing hosts.
How do I fix CVE-2026-24097?
To fix CVE-2026-24097, upgrade Checkmk to version 2.4.0p23 or 2.3.0p43 or later.
What versions of Checkmk are affected by CVE-2026-24097?
CVE-2026-24097 affects Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and all versions of 2.2.0.
What type of vulnerability is CVE-2026-24097?
CVE-2026-24097 is an authenticated host enumeration vulnerability that results from observable response discrepancies.
Who is impacted by CVE-2026-24097?
Authentic users of Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 are impacted by CVE-2026-24097.