Checkmk REST API Quick Setup Endpoints Insufficient Permission Validation Vulnerability

Vulnerability

A vulnerability exists in the Checkmk REST API Quick Setup endpoints in versions 2.5.0 (beta) prior to 2.5.0b2 and 2.4.0 prior to 2.4.0p25. The issue arises from inadequate permission validation, allowing low-privileged users to perform unauthorized actions or access sensitive information. Before the fix, authenticated users could interact with the Quick Setup endpoints to edit setups, check background job statuses, and execute Quick Setup actions. The lack of granular authorization checks meant that users could manipulate stage data and potentially disclose sensitive information by reading the state of background jobs.

Impact

Exploitation of this vulnerability could lead to unauthorized actions being performed on Quick Setup endpoints, allowing low-privileged users to edit setups, execute Quick Setup actions, and access sensitive information through background job statuses.

Remediation

Users can upgrade to Checkmk versions 2.5.0b2 or 2.4.0p26 to address this vulnerability.

Added: Apr 1, 2026, 11:19 AM
Updated: Apr 1, 2026, 11:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
1.3
exploitability
5.2
remediation
7.7
relevance
5.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.