CVE-2026-3103

MEDIUM WAF: Low
CVSS 5.4 Published: 2026-03-04
CWE-863

A logic error in the remove_password() function in Checkmk GmbH's Checkmk versions <2.4.0p23, <2.3.0p43, and 2.2.0 (EOL) allows a low-privileged user to cause data loss.

WAF Coverage Analysis

Incorrect Authorization Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
checkmkcheckmk2.2.0
checkmkcheckmk2.3.0
checkmkcheckmk2.3.0
checkmkcheckmk2.3.0
checkmkcheckmk2.3.0
checkmkcheckmk2.3.0
checkmkcheckmk2.3.0
checkmkcheckmk2.3.0
checkmkcheckmk2.3.0
checkmkcheckmk2.3.0

References

Back to CVE Database