SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-15227

MEDIUM · CVSS 5.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

Checkmk versions prior to 2.5.0p10, 2.4.0p35, and 2.3.0p49, as well as the end-of-life version 2.2.0, are vulnerable due to a missing authorization flaw that permits authenticated users without the "Edit foreign Reports" permission to alter reports created by other users. This vulnerability can lead to unauthorized modifications of sensitive reporting data, potentially compromising the integrity of the reports. Organizations using affected versions should prioritize remediation to safeguard report integrity and maintain user trust.

CVE
CVE-2026-15227
Severity
MEDIUM
CVSS
5.3
EPSS
0.21%

Original NVD Description

Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" permission to modify reports owned by other users.