{"id":"CVE-2025-58121","summary":"Insufficient permission validation on multiple REST API endpoints","details":"Insufficient permission validation on multiple REST API endpoints in Checkmk 2.2.0, 2.3.0, and 2.4.0 before version 2.4.0p16 allows low-privileged users to perform unauthorized actions or obtain sensitive information","modified":"2026-08-12T03:51:37.496618516Z","published":"2025-11-18T15:11:35.167Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"2.4.0"},{"fixed":"2.4.0p16"},{"introduced":"2.3.0"},{"last_affected":"2.3.0"},{"introduced":"2.2.0"},{"last_affected":"2.2.0"}],"source":"AFFECTED_FIELD"},{"source":"CPE_FIELD","extracted_events":[{"introduced":"2.4.0"},{"fixed":"2.4.0p16"}]},{"extracted_events":[{"introduced":"2.4.0"},{"fixed":"2.4.0p16"}],"source":"DESCRIPTION"}],"cna_assigner":"Checkmk","cwe_ids":["CWE-280"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/58xxx/CVE-2025-58121.json"},"references":[{"type":"WEB","url":"https://checkmk.com/werk/18983"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/58xxx/CVE-2025-58121.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58121"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/checkmk/checkmk","events":[{"introduced":"d6049cd2d82eba3842b30c305912b9e946842463"},{"fixed":"4abde4a41de677e103561e4fb75b81f6ee8b80dd"},{"introduced":"4abde4a41de677e103561e4fb75b81f6ee8b80dd"},{"last_affected":"df508000718009a401a35af049c246997421bdba"}],"database_specific":{"cpe":["cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.4.0:-:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.4.0:b1:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.4.0:p1:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.4.0:b2:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.4.0:p2:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.4.0:b3:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.4.0:p3:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.4.0:b4:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.4.0:p4:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.4.0:b5:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.4.0:p5:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.4.0:b6:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.4.0:p6:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.4.0:p10:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.4.0:p11:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.4.0:p12:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.4.0:p13:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.4.0:p14:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.4.0:p15:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.4.0:p7:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.4.0:p8:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.4.0:p9:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.2.0"},{"fixed":"2.4.0"},{"introduced":"2.4.0-NA"},{"last_affected":"2.4.0-NA"},{"introduced":"2.4.0-b1"},{"last_affected":"2.4.0-b1"},{"introduced":"2.4.0-p1"},{"last_affected":"2.4.0-p1"},{"introduced":"2.4.0-b2"},{"last_affected":"2.4.0-b2"},{"introduced":"2.4.0-p2"},{"last_affected":"2.4.0-p2"},{"introduced":"2.4.0-b3"},{"last_affected":"2.4.0-b3"},{"introduced":"2.4.0-p3"},{"last_affected":"2.4.0-p3"},{"introduced":"2.4.0-b4"},{"last_affected":"2.4.0-b4"},{"introduced":"2.4.0-p4"},{"last_affected":"2.4.0-p4"},{"introduced":"2.4.0-b5"},{"last_affected":"2.4.0-b5"},{"introduced":"2.4.0-p5"},{"last_affected":"2.4.0-p5"},{"introduced":"2.4.0-b6"},{"last_affected":"2.4.0-b6"},{"introduced":"2.4.0-p6"},{"last_affected":"2.4.0-p6"},{"introduced":"2.4.0-p10"},{"last_affected":"2.4.0-p10"},{"introduced":"2.4.0-p11"},{"last_affected":"2.4.0-p11"},{"introduced":"2.4.0-p12"},{"last_affected":"2.4.0-p12"},{"introduced":"2.4.0-p13"},{"last_affected":"2.4.0-p13"},{"introduced":"2.4.0-p14"},{"last_affected":"2.4.0-p14"},{"introduced":"2.4.0-p15"},{"last_affected":"2.4.0-p15"},{"introduced":"2.4.0-p7"},{"last_affected":"2.4.0-p7"},{"introduced":"2.4.0-p8"},{"last_affected":"2.4.0-p8"},{"introduced":"2.4.0-p9"},{"last_affected":"2.4.0-p9"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["2.4.0-NA","2.4.0-b1","2.4.0-b2","2.4.0-b3","2.4.0-b4","2.4.0-b5","2.4.0-b6","2.4.0-p10","2.4.0-p11","2.4.0-p12","2.4.0-p13","2.4.0-p14","2.4.0-p15","2.4.0-p7","2.4.0-p8","2.4.0-p9","v2.4.0p9-rc2","v2.4.0p9","v2.4.0p9-rc1","v2.4.0p8-rc1","v2.4.0p7-rc1","v2.4.0p6-rc1","v2.4.0p6","v2.4.0p5-rc1","v2.4.0p4-rc1","v2.4.0p4","v2.4.0p3-rc1","v2.4.0p2-rc1","v2.4.0p2","v2.4.0p1-rc1","v2.4.0-rc1","v2.4.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-58121.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}]}