CVE-2026-61552
Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes attacker-controlled template names into generated configuration without escaping them. An authenticated ApiUser with an objects/create/* permission can inject Icinga 2 DSL configuration, escape the intended object, create additional objects, and exceed the user's assigned privileges. This issue is fixed in versions 2.14.9, 2.15.4, and 2.16.2.
Schwachstellenklasse
Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes attacker-controlled template names into generated configuration without escaping them. An authenticated ApiUser with an objects/create/* permission can inject Icinga 2 DSL configuration, escape the intended object, create additional objects, and exceed the user's assigned privileges. This issue is fixed in versions 2.14.9, 2.15.4, and 2.16.2.
Quellen
- https://github.com/Icinga/icinga2/commit/125b7734e84d03f09b79d36c270152b11629a8c5
- https://github.com/Icinga/icinga2/commit/af4b36e6464b9b214bed270a53d6474cf91eb441
- https://github.com/Icinga/icinga2/commit/eec0d90e8303376fe772b3e4a04e3b064a44cf30
- https://github.com/Icinga/icinga2/commit/faf0450962ad678397991cfdf041810feafa71e7
- https://github.com/Icinga/icinga2/pull/10910
- https://github.com/Icinga/icinga2/releases/tag/v2.14.9
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.