📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global insider Education HIGH 6h Global supply_chain Software Development and Technology HIGH 11h Global apt Government/Critical Infrastructure CRITICAL 12h Global vulnerability Enterprise Software / Data Analytics CRITICAL 13h Global vulnerability Artificial Intelligence and Technology HIGH 17h Global general Technology and Artificial Intelligence MEDIUM 20h Global general Technology and Artificial Intelligence HIGH 21h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 6h Global supply_chain Software Development and Technology HIGH 11h Global apt Government/Critical Infrastructure CRITICAL 12h Global vulnerability Enterprise Software / Data Analytics CRITICAL 13h Global vulnerability Artificial Intelligence and Technology HIGH 17h Global general Technology and Artificial Intelligence MEDIUM 20h Global general Technology and Artificial Intelligence HIGH 21h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 6h Global supply_chain Software Development and Technology HIGH 11h Global apt Government/Critical Infrastructure CRITICAL 12h Global vulnerability Enterprise Software / Data Analytics CRITICAL 13h Global vulnerability Artificial Intelligence and Technology HIGH 17h Global general Technology and Artificial Intelligence MEDIUM 20h Global general Technology and Artificial Intelligence HIGH 21h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d
Vulnerabilities

CVE-2026-24096

High
CWE-280 — Weakness Type
Published: Apr 1, 2026  ·  Modified: Apr 8, 2026  ·  Source: NVD
CVSS v3
8.8
🔗 NVD Official
📄 Description (English)

Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5.0b2 and 2.4.0 before version 2.4.0p25 allows low-privileged users to perform unauthorized actions or obtain sensitive information

🤖 AI Executive Summary

CVE-2026-24096 is a privilege escalation vulnerability in Checkmk monitoring platform affecting versions 2.4.0 through 2.4.0p24 and 2.5.0 beta versions before 2.5.0b2. Low-privileged users can bypass permission validation on REST API Quick Setup endpoints to perform unauthorized administrative actions or access sensitive monitoring data. With a CVSS score of 8.8 and no patch currently available, this poses significant risk to Saudi organizations relying on Checkmk for infrastructure monitoring.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Apr 22, 2026 18:41
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability directly impacts Saudi organizations using Checkmk for IT infrastructure monitoring, particularly: (1) Banking sector (SAMA-regulated banks) — unauthorized access to monitoring data could expose system health information and enable lateral movement; (2) Government agencies (NCA oversight) — critical infrastructure monitoring systems could be compromised; (3) Energy sector (ARAMCO, utilities) — SCADA/OT monitoring systems relying on Checkmk could be manipulated; (4) Telecommunications (STC, Mobily) — network monitoring infrastructure at risk; (5) Healthcare institutions — patient data systems monitoring could be compromised. The privilege escalation nature allows attackers to move from low-privilege accounts to administrative control of monitoring infrastructure.
🏢 Affected Saudi Sectors
Banking and Financial Services Government and Public Administration Energy and Utilities Telecommunications Healthcare Critical Infrastructure Manufacturing
⚖️ Saudi Risk Score (AI)
8.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Inventory all Checkmk deployments in your organization and identify versions 2.4.0-2.4.0p24 and 2.5.0 beta versions before 2.5.0b2
2. Restrict network access to Checkmk REST API endpoints to authorized administrative networks only using firewall rules
3. Implement strict RBAC — audit all user accounts and remove unnecessary API access permissions
4. Enable comprehensive API logging and monitoring for Quick Setup endpoints (/api/v0/domain-types/quick_setup*)
5. Monitor for suspicious API calls from low-privileged accounts attempting administrative operations

COMPENSATING CONTROLS (until patch available):
6. Deploy WAF rules to block unauthorized REST API calls to Quick Setup endpoints from non-admin sources
7. Implement API rate limiting and anomaly detection on Checkmk API endpoints
8. Use reverse proxy authentication to enforce additional MFA for API access
9. Segment Checkmk infrastructure on isolated network with restricted access

DETECTION RULES:
10. Monitor for HTTP 200/201 responses on /api/v0/domain-types/quick_setup* endpoints from non-admin user accounts
11. Alert on API calls modifying monitoring configurations from accounts without admin role
12. Track failed authentication attempts followed by successful API calls from same source
13. Monitor for privilege escalation patterns in Checkmk audit logs

PATCHING GUIDANCE:
14. Subscribe to Checkmk security advisories for patch availability (expected 2.4.0p25 and 2.5.0b2)
15. Plan immediate patching upon release — test in non-production environment first
16. For critical deployments, consider temporary migration to patched version or alternative monitoring solution
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. قم بحصر جميع نشرات Checkmk في مؤسستك وحدد الإصدارات 2.4.0-2.4.0p24 وإصدارات 2.5.0 التجريبية قبل 2.5.0b2
2. قيد الوصول إلى نقاط نهاية REST API في Checkmk إلى الشبكات الإدارية المصرح بها فقط باستخدام قواعد جدار الحماية
3. طبق RBAC صارم — قم بتدقيق جميع حسابات المستخدمين وأزل أذونات الوصول إلى API غير الضرورية
4. فعّل تسجيل المراقبة الشاملة لنقاط نهاية Quick Setup (/api/v0/domain-types/quick_setup*)
5. راقب استدعاءات API المريبة من حسابات ذات امتيازات منخفضة تحاول إجراء عمليات إدارية

الضوابط البديلة (حتى توفر التصحيح):
6. نشر قواعد WAF لحظر استدعاءات REST API غير المصرح بها إلى نقاط نهاية Quick Setup من مصادر غير إدارية
7. طبق تحديد معدل API والكشف عن الشذوذ على نقاط نهاية Checkmk API
8. استخدم المصادقة عبر الوكيل العكسي لفرض MFA إضافي لوصول API
9. قسّم البنية التحتية لـ Checkmk على شبكة معزولة مع وصول مقيد

قواعد الكشف:
10. راقب استجابات HTTP 200/201 على نقاط نهاية /api/v0/domain-types/quick_setup* من حسابات المستخدمين غير الإداريين
11. أصدر تنبيهات لاستدعاءات API التي تعدل تكوينات المراقبة من حسابات بدون دور إداري
12. تتبع محاولات المصادقة الفاشلة متبوعة باستدعاءات API ناجحة من نفس المصدر
13. راقب أنماط تصعيد الامتيازات في سجلات تدقيق Checkmk

إرشادات التصحيح:
14. اشترك في تنبيهات أمان Checkmk لتوفر التصحيح (متوقع 2.4.0p25 و 2.5.0b2)
15. خطط للتصحيح الفوري عند الإصدار — اختبر في بيئة غير الإنتاج أولاً
16. بالنسبة للنشرات الحرجة، فكر في الهجرة المؤقتة إلى إصدار مصحح أو حل مراقبة بديل
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.5.1.1 — Access Control Policy (unauthorized API access) ECC 2024 A.5.2.1 — User Registration and Access Rights Management ECC 2024 A.5.3.1 — Management of Privileged Access Rights ECC 2024 A.8.2.1 — User Access Management ECC 2024 A.9.2.1 — User Access Rights Review
🔵 SAMA CSF
SAMA CSF ID.AM-1 — Asset Management (inventory Checkmk instances) SAMA CSF PR.AC-1 — Access Control Policy (enforce least privilege) SAMA CSF PR.AC-4 — Access Rights Management (validate permissions) SAMA CSF DE.CM-1 — Detection and Analysis (monitor API activity) SAMA CSF RS.MI-2 — Incident Response (contain privilege escalation)
🟡 ISO 27001:2022
ISO 27001:2022 A.5.2 — Information Security Policies (access control) ISO 27001:2022 A.6.2 — Internal Organization (segregation of duties) ISO 27001:2022 A.8.2 — Asset Management (inventory and control) ISO 27001:2022 A.9.1 — Access Control (user access management) ISO 27001:2022 A.9.2 — User Access Management (privilege management) ISO 27001:2022 A.9.4 — Access Control to Information and Other Associated Assets
🟣 PCI DSS v4.0.1
PCI DSS 2.1 — Restrict access to system components by business need PCI DSS 6.5.10 — Broken authentication and session management PCI DSS 7.1 — Limit access to system components by business need PCI DSS 8.1 — Assign unique ID to each person with computer access
📦 Affected Products / CPE 32 entries
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.4.0
checkmk:checkmk:2.5.0
📊 CVSS Score
8.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score8.8
CWECWE-280
EPSS0.04%
Exploit No
Patch ✗ No
Published 2026-04-01
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
8.2
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-280
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.