← Back to CVE List
CVE-2026-61550NVD
Vulnerability Summary
Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker able to connect to TCP port 5665 can replace the node certificate and trusted CA certificate, impersonate a trusted node, and take control of the node. This issue is fixed in versions 2.14.9, 2.15.4, and 2.16.2.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
External References
- https://github.com/Icinga/icinga2/security/advisories/GHSA-vj39-ww8j-vvx5
- https://github.com/Icinga/icinga2/pull/10907
- https://github.com/Icinga/icinga2/commit/4b7fb3405f4616a24b2b55e20f603a56b7dd6ad0
- https://github.com/Icinga/icinga2/commit/6c2e0db3819f859910a4ae265461cb51b1d2039c
- https://github.com/Icinga/icinga2/commit/a6f7cc7a4ef8beed023b24416106822d6940c4c0
- https://github.com/Icinga/icinga2/commit/d37b0cfd7d9595ae2f02fadb3d724c98d8620f81
- https://github.com/Icinga/icinga2/releases/tag/v2.14.9
- https://github.com/Icinga/icinga2/releases/tag/v2.15.4
- https://github.com/Icinga/icinga2/releases/tag/v2.16.2
- https://icinga.com/blog/icinga2-security-release-v2-16-2