SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-15937

MEDIUM · CVSS 5.3 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Improper certificate validation in Checkmk versions prior to 2.5.0p10 allows relay and push agents with the same UUID to misuse each other's mTLS certificates for authentication, potentially leading to unauthorized access to agent receiver endpoints. This vulnerability could enable attackers to impersonate legitimate agents, compromising the integrity of the system. Organizations using Checkmk should prioritize addressing this issue to safeguard their network communications.

CVE
CVE-2026-15937
Severity
MEDIUM
CVSS
5.3
EPSS
0.14%

Original NVD Description

Improper certificate validation in Checkmk <2.5.0p10 allows a relay and a push agent that share the same UUID to reuse each other's mTLS certificate to authenticate against agent receiver endpoints in either direction, because the endpoints do not verify that the certificate was issued by their own root certificate.