NONE · 0

CVE-2026-15937

Improper certificate validation in Checkmk <2.5.0p10 allows a relay and a push agent that share the same UUID to reuse each other's mTLS certificate to authenticate against agent receiver endpoints in...

Vulnerability Description

Improper certificate validation in Checkmk <2.5.0p10 allows a relay and a push agent that share the same UUID to reuse each other's mTLS certificate to authenticate against agent receiver endpoints in either direction, because the endpoints do not verify that the certificate was issued by their own root certificate.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-15937?

CVE-2026-15937 is a documented vulnerability. Improper certificate validation in Checkmk <2.5.0p10 allows a relay and a push agent that share the same UUID to reuse each other's mTLS certificate to authenticate against agent receiver endpoints in...

How severe is CVE-2026-15937?

CVSS scoring is not yet available for CVE-2026-15937. Check NVD for updates.

Is there a patch for CVE-2026-15937?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.