CVE-2026-2859: Unauthenticated Host Enumeration via Observable Response Discrepancy on Deploy Agent Endpoint
Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows unauthenticated users to enumerate existing hosts by observing different HTTP response codes in deployagent endpoint, which could lead to information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2859?
CVE-2026-2859 has been classified as a medium severity vulnerability that affects specific versions of Checkmk.
How do I fix CVE-2026-2859?
To fix CVE-2026-2859, update your Checkmk installation to versions 2.4.0p23 or higher, or 2.3.0p43 or higher.
Which versions of Checkmk are affected by CVE-2026-2859?
CVE-2026-2859 affects Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0.
What type of access can attackers gain from CVE-2026-2859?
Attackers exploiting CVE-2026-2859 can perform unauthenticated host enumeration, leading to the exposure of existing hosts.
Is there a workaround for CVE-2026-2859 until a fix is applied?
There are no known workarounds for CVE-2026-2859; upgrading to a fixed version is the recommended action.