Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-61550: Icinga 2 can be taken over via untrusted certificate updates
CVE-2026-61550 · published 7 days ago
Summary
Versions of Icinga 2 from 2.8 up to 2.14.9, 2.15.4 and 2.16.2 do not check who is sending certificate‑update messages. An attacker who can reach the monitoring port (5665) could replace the node’s security certificates and pretend to be a trusted system, gaining control of that node. Upgrade to Icinga 2 version 2.14.9, 2.15.4 or 2.16.2 (or later) to fix the problem.
What to do
- Update debian icinga2 to version 2.14.6-1+deb13u1.
- Update debian icinga2 to version 2.16.2-1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | icinga | icinga2 | >= 2.8, < 2.14.9 |
| Debian:12 | debian | icinga2 | All versions |
| Debian:13 | debian | icinga2 |
< 2.14.6-1+deb13u1 Fix: upgrade to 2.14.6-1+deb13u1
|
| Debian:14 | debian | icinga2 |
< 2.16.2-1 Fix: upgrade to 2.16.2-1
|
| Ubuntu:16.04:LTS | canonical | icinga2 | All versions |
Original advisory text
Icinga 2: Improper access control for JSON-RPC update certificate messages
Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker able to connect to TCP port 5665 can replace the node certificate and trusted CA certificate, impersonate a trusted node, and take control of the node. This issue is fixed in versions 2.14.9, 2.15.4, and 2.16.2.
References
- https://github.com/Icinga/icinga2/pull/10907
- https://github.com/Icinga/icinga2/commit/4b7fb3405f4616a24b2b55e20f603a56b7dd6ad...
- https://github.com/Icinga/icinga2/commit/6c2e0db3819f859910a4ae265461cb51b1d2039...
- https://github.com/Icinga/icinga2/commit/a6f7cc7a4ef8beed023b24416106822d6940c4c...
- https://github.com/Icinga/icinga2/commit/d37b0cfd7d9595ae2f02fadb3d724c98d8620f8...
- https://github.com/Icinga/icinga2/releases/tag/v2.14.9
- https://icinga.com/blog/icinga2-security-release-v2-16-2
- https://github.com/Icinga/icinga2/releases/tag/v2.15.4
- https://github.com/Icinga/icinga2/releases/tag/v2.16.2
- https://github.com/Icinga/icinga2/security/advisories/GHSA-vj39-ww8j-vvx5
- https://security-tracker.debian.org/tracker/CVE-2026-61550 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61550... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-61550 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-61550 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-61550 Third Party Advisory
- https://icinga.com/blog/icinga2-security-release-v2-16-2/ Third Party Advisory
Severity
9.8
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-862Missing Authorization
Timeline
Published18 Sep 2026
Updated25 Sep 2026
First seen18 Sep 2026
Sources
CVE-2026-61550 · NVD
CVE-2026-61550 · MITRE
DEBIAN-CVE-2026-61550 · OSV
CVE-2026-61550 · OSV
GHSA-vj39-ww8j-vvx5 · GHSA
UBUNTU-CVE-2026-61550 · OSV
Track software like this
Free during beta