Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass mutual TLS client certificate verification of relay endpoints by supplying a fixed placeholder identity in the request URL, resulting in limited impact on integrity and availability. Only the Cloud, Ultimate and Ultimate MT editions are affected, as other editions do not expose relay endpoints.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://checkmk.com/werk/20174 |
|
History
Fri, 21 Aug 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass mutual TLS client certificate verification of relay endpoints by supplying a fixed placeholder identity in the request URL, resulting in limited impact on integrity and availability. Only the Cloud, Ultimate and Ultimate MT editions are affected, as other editions do not expose relay endpoints. | |
| Title | Agent receiver accepts mTLS requests without a client certificate | |
| First Time appeared |
Checkmk
Checkmk checkmk |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Checkmk
Checkmk checkmk |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Checkmk
Published:
Updated: 2026-08-21T11:53:45.355Z
Reserved: 2026-07-13T08:39:03.953Z
Link: CVE-2026-15576
No data.
Status : Received
Published: 2026-08-21T11:17:04.463
Modified: 2026-08-21T11:17:04.463
Link: CVE-2026-15576
No data.
OpenCVE Enrichment
No data.
Weaknesses