Incorrect authorization in the User Messages dashboard...
Moderate severity
Unreviewed
Published
Jun 8, 2026
to the GitHub Advisory Database
•
Updated Jun 9, 2026
Description
Published by the National Vulnerability Database
Jun 8, 2026
Published to the GitHub Advisory Database
Jun 8, 2026
Last updated
Jun 9, 2026
Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creator's messages rather than the viewer's, allowing an attacker who knows a valid public dashboard share token to read the issuer's personal messages by sending requests to the underlying endpoint, even without a User Messages widget present.
References