« Volver al listado

CVE-2026-7765

Estado: AnalizadaMedia (6.3)—

Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creator's messages rather than the viewer's, allowing an attacker who knows a valid public dashboard share token to read the issuer's personal messages by sending requests to the underlying endpoint, even without a User Messages widget present.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-7765",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-7765",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-08T13:04:52.177100Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "security@checkmk.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 6.3,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "PRESENT",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "LOW",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "security@checkmk.com",
      "affectedData": [
        {
          "vendor": "Checkmk GmbH",
          "product": "Checkmk",
          "versions": [
            {
              "status": "affected",
              "version": "2.5.0",
              "lessThan": "2.5.0p5",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-06-08T13:16:33.627",
  "references": [
    {
      "url": "https://checkmk.com/werk/19815",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@checkmk.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@checkmk.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creator's messages rather than the viewer's, allowing an attacker who knows a valid public dashboard share token to read the issuer's personal messages by sending requests to the underlying endpoint, even without a User Messages widget present."
    },
    {
      "lang": "es",
      "value": "Autorización incorrecta en el widget del panel de control de Mensajes de Usuario en Checkmk <2.5.0p5 provoca que los puntos finales de recuperación de mensajes devuelvan los mensajes del creador del panel de control en lugar de los del espectador, permitiendo a un atacante que conoce un token de compartición de panel de control público válido leer los mensajes personales del emisor enviando solicitudes al punto final subyacente, incluso sin un widget de Mensajes de Usuario presente."
    }
  ],
  "lastModified": "2026-07-23T07:10:00.113",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:checkmk:checkmk:2.5.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7797AFCE-3FF9-497C-AEA9-D6CF170F056D"
            },
            {
              "criteria": "cpe:2.3:a:checkmk:checkmk:2.5.0:b1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F8943BB3-1487-494C-B4EB-89EB0B18B6A2"
            },
            {
              "criteria": "cpe:2.3:a:checkmk:checkmk:2.5.0:b2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5342045D-CB9F-4663-9538-8B657C9AC833"
            },
            {
              "criteria": "cpe:2.3:a:checkmk:checkmk:2.5.0:b3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9566834-D4EE-4104-AD60-7988FCF17224"
            },
            {
              "criteria": "cpe:2.3:a:checkmk:checkmk:2.5.0:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F53BB4AD-54A6-4A77-868A-D6972DDF0EAA"
            },
            {
              "criteria": "cpe:2.3:a:checkmk:checkmk:2.5.0:p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0405E40E-7969-49B3-90EC-98A982464275"
            },
            {
              "criteria": "cpe:2.3:a:checkmk:checkmk:2.5.0:p3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "629E039F-1C52-48DF-A952-11220A890AC2"
            },
            {
              "criteria": "cpe:2.3:a:checkmk:checkmk:2.5.0:p4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CDC5BD88-F1D9-4ED4-81AA-3E6CD9AF16A8"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@checkmk.com"
}