CVE-2026-7485: Frozen BI aggregations leak host and service names to unauthorized users
Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allows an authenticated user with restricted host and service visibility to learn the names and the existence of hosts and services they are not authorized to see.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Checkmkto a version that resolves this vulnerability.Fixed in 2.5.0p2 - Upgrade
Upgrade
Checkmkto a version that resolves this vulnerability.Fixed in 2.4.0p29 - Upgrade
Upgrade
Checkmkto a version that resolves this vulnerability.Fixed in 2.3.0p47
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated Checkmk user whose visibility is restricted to only some hosts and services can exploit the issue. The exposure is limited to disclosure of names and the existence of hosts and services outside that user's authorized visibility.
Which deployments are affected?
Affected versions are Checkmk earlier than 2.5.0p2, 2.4.0p29, and 2.3.0p47, as well as all 2.2.0 versions. The issue concerns frozen BI aggregations.