Back

MEDIUM

User Messages widget leaked issuer messages on shared dashboards

Published Jun 8, 2026

Description

Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creator's messages rather than the viewer's, allowing an attacker who knows a valid public dashboard share token to read the issuer's personal messages by sending requests to the underlying endpoint, even without a User Messages widget present.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Checkmk
Published Jun 8, 2026
Updated Jun 8, 2026
Reserved May 4, 2026
CISA Vulnrichment
Updated Jun 8, 2026
NVD
Status Analyzed
Modified Oct 6, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Checkmk
Published Jun 8, 2026
Updated Jun 8, 2026
Exploited since n/a
EUVD-2026-35051