These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-15576 is an improper authentication vulnerability in Checkmk's agent receiver. An unauthenticated remote attacker can bypass mutual TLS client certificate verification of relay endpoints by supplying a fixed placeholder identity in the request URL. This affects Checkmk Cloud, Ultimate, and Ultimate MT editions prior to version 2.5.0p10. The vulnerability has a CVSS score of 6.9 and a MEDIUM sever [truncated]
CVE-2026-7485 is a vulnerability in Checkmk versions before 2.5.0p2, 2.4.0p29, 2.3.0p47, and all 2.2.0 versions. The issue allows an authenticated user with restricted host and service visibility to learn names and existence of hosts and services they are not authorized to see due to incorrect authorization in frozen BI aggregations. This could potentially lead to unauthorized access or information disclo [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-15227 was published on 2026-07-31T13:17:19.593Z and has not been modified since then. This CVE addresses a medium-severity vulnerability in Checkmk versions before 2.5.0p10, 2.4.0p35, 2.3.0p49, and 2.2.0, allowing authenticated users lacking 'Edit foreign Reports' permission to modify reports owned by other use [truncated]
CVE-2026-8593 is an improper permission enforcement vulnerability affecting Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL). This vulnerability allows users without permissions to view and modify BI packs and rules. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Users of Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, [truncated]
CVE-2026-14852 is a privilege escalation vulnerability in Checkmk. A local unprivileged user can execute arbitrary commands as root by starting a process crafted to look like a SAP HANA instance. This vulnerability affects Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL). Users of these versions should apply patches to prevent local privilege escalation.
CVE-2026-9549 is a MEDIUM severity vulnerability in Checkmk versions before 2.5.0p5, 2.4.0p31, 2.3.0p48, and all 2.2.0 versions. This vulnerability allows an administrator who can configure active or custom checks to inject malicious HTML or JavaScript into check output that executes in the browser of an admin or a user with host read permissions when they run the check on the service discovery page.
CVE-2026-8833 is a HIGH severity vulnerability in Checkmk versions <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions. It allows an authenticated user to bypass URL validation and inject malicious URLs such as javascript: URIs, resulting in cross-site scripting when another user interacts with the crafted link.
CVE-2026-8078 is a MEDIUM severity vulnerability in Checkmk versions <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions. An administrator can store malicious HTML or JavaScript in changelog messages that executes in other users' browsers when they view the Activate Changes page or Audit log.
CVE-2026-7765 is a medium-severity vulnerability in Checkmk versions prior to 2.5.0p5. The issue lies in the User Messages dashboard widget, where incorrect authorization allows an attacker with a valid public dashboard share token to read the dashboard creator's personal messages by sending requests to the underlying endpoint, even without a User Messages widget present.
CVE-2026-7186 is a HIGH severity vulnerability in Checkmk versions <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions. It allows users with dashboard editing permissions to store a URL with a dangerous URI scheme, such as javascript:, that executes scripts in other users' browsers when they view the dashboard.
CVE-2026-20915 is a Stored cross-site scripting (XSS) vulnerability in Checkmk version 2.5.0 (beta) before 2.5.0b2 that allows authenticated users with permission to create pending changes to inject malicious JavaScript into the Pending Changes sidebar. The injected JavaScript will execute in the browsers of other users viewing the sidebar. This issue has a CVSS score of 8.5 and a severity of HIGH. The vu [truncated]