What is CVE-2026-15227?
This vulnerability is a missing authorization flaw in Checkmk that allows an authenticated user without the "Edit foreign Reports" permission to modify reports owned by other users. It affects Checkmk versions below 2.3.0p49, 2.4.0p35, and 2.5.0p10. Users are advised to update to the recommended patched versions.
Azərbaycanca: Bu zəiflik Checkmk proqramında "Edit foreign Reports" icazəsi olmayan autentifikasiya olunmuş istifadəçiyə başqa istifadəçilərin hesabatlarını dəyişməyə imkan verən authorization çatışmazlığıdır. 2.3.0p49, 2.4.0p35, 2.5.0p10 versiyalarından aşağı olan Checkmk məhsulları təsirlənir. İstifadəçilərə tövsiyə olunan müvafiq versiyalara yeniləmə etməkdir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which Checkmk versions are affected by CVE-2026-15227?
Checkmk versions below 2.3.0p49, 2.4.0p35, and 2.5.0p10 are affected by this vulnerability.
What permissions does an attacker need to exploit CVE-2026-15227?
An attacker must be an authenticated user but does not need the 'Edit foreign Reports' permission.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.