Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-61550: Icinga 2 can be taken over via untrusted certificate updates

CVE-2026-61550 · published 7 days ago
Summary

Versions of Icinga 2 from 2.8 up to 2.14.9, 2.15.4 and 2.16.2 do not check who is sending certificate‑update messages. An attacker who can reach the monitoring port (5665) could replace the node’s security certificates and pretend to be a trusted system, gaining control of that node. Upgrade to Icinga 2 version 2.14.9, 2.15.4 or 2.16.2 (or later) to fix the problem.

What to do
  • Update debian icinga2 to version 2.14.6-1+deb13u1.
  • Update debian icinga2 to version 2.16.2-1.
Affected software
Ecosystem VendorProductAffected versions
– icinga icinga2 >= 2.8, < 2.14.9
Debian:12 debian icinga2 All versions
Debian:13 debian icinga2 < 2.14.6-1+deb13u1
Fix: upgrade to 2.14.6-1+deb13u1
Debian:14 debian icinga2 < 2.16.2-1
Fix: upgrade to 2.16.2-1
Ubuntu:16.04:LTS canonical icinga2 All versions
Original advisory text
Icinga 2: Improper access control for JSON-RPC update certificate messages
Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker able to connect to TCP port 5665 can replace the node certificate and trusted CA certificate, impersonate a trusted node, and take control of the node. This issue is fixed in versions 2.14.9, 2.15.4, and 2.16.2.
Severity
9.8 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-862Missing Authorization
Timeline
Published18 Sep 2026
Updated25 Sep 2026
First seen18 Sep 2026
Track software like this
Free during beta