CVE-2026-8593: Fix Business Intelligence API Pack permission
Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to view and modify BI packs and rules
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Checkmk Business Intelligence (BI) API Packto a version that resolves this vulnerability.Fixed in 2.5.0p9 - Upgrade
Upgrade
Checkmk Business Intelligence (BI) API Packto a version that resolves this vulnerability.Fixed in 2.4.0p34 - Upgrade
Upgrade
Checkmk Business Intelligence (BI) API Packto a version that resolves this vulnerability.Fixed in 2.3.0p49
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8593?
The severity of CVE-2026-8593 is rated as medium with a CVSS score of 5.3.
How do I fix CVE-2026-8593?
To fix CVE-2026-8593, update Checkmk to versions 2.5.0p9 or later, 2.4.0p34 or later, or 2.3.0p49 or later.
What types of permissions are improperly enforced in CVE-2026-8593?
CVE-2026-8593 allows users without permissions to view and modify Business Intelligence packs and rules.
Which versions of Checkmk are affected by CVE-2026-8593?
CVE-2026-8593 affects Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0.
What is the risk associated with CVE-2026-8593?
CVE-2026-8593 poses a risk score of 43, indicating significant risk due to improper permission enforcement.