TROYANOSYVIRUS
Back to CVEs

CVE-2026-24097

MEDIUM
4.3

Description

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows authenticated users to enumerate existing hosts by observing different HTTP response codes in agent-receiver/register_existing endpoint, which could lead to information disclosure.

CVE Details

CVSS v3.1 Score4.3
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published3/13/2026
Last Modified3/18/2026
Sourcenvd
Honeypot Sightings0

Affected Products

checkmk:checkmk

Weaknesses (CWE)

CWE-204

References

https://checkmk.com/werk/18993(security@checkmk.com)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.