Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Icinga — Vulnerabilities & Security Advisories 31

Browse all 31 CVE security advisories affecting Icinga. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Icinga is an open-source network monitoring system designed to track the availability and performance of IT infrastructure components, serving as a scalable alternative to Nagios. Its architecture relies on a master-satellite topology, allowing distributed monitoring across complex environments. Historically, security assessments have identified vulnerabilities primarily within its web interface and API components, with common flaw classes including cross-site scripting (XSS), improper access control, and remote code execution (RCE). These issues often stem from insufficient input validation or misconfigured permissions in older releases. While no single catastrophic breach has defined its public history, the accumulation of twenty-seven recorded CVEs highlights the necessity for rigorous patch management. Administrators must prioritize updating to mitigate risks associated with exposed endpoints, ensuring that the monitoring tool itself does not become an entry point for attackers seeking to compromise underlying network assets.

Found 12 results / 31 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-61552 Icinga 2 DSL Injection via Unescaped Import Template Name — icinga2 CWE-94 7.2 High 2026-09-18
CVE-2026-61551 Icinga 2: Stack overflow via deeply nested JSON objects — icinga2 CWE-674 8.6 High 2026-09-18
CVE-2026-61550 Icinga 2: Improper access control for JSON-RPC update certificate messages — icinga2 CWE-862 9.8 Critical 2026-09-18
CVE-2026-24413 Icinga has insecure permission of %ProgramData%\icinga2\var on Windows — icinga2 CWE-276 5.5AI Medium AI 2026-01-29
CVE-2025-61909 Icinga 2 signals sent as root to processes based on PID file written by the Icinga 2 daemon user — icinga2 CWE-250 3.3AI Low AI 2025-10-16
CVE-2025-61908 Icinga 2 Denial of Service (DoS) By Dereferencing Invalid Reference — icinga2 CWE-476 6.5AI Medium AI 2025-10-16
CVE-2025-61907 Icinga 2 API users could access restricted values in filter expressions — icinga2 CWE-200 6.5AI Medium AI 2025-10-16
CVE-2025-48057 Icinga 2 certificate renewal might incorrectly renew an invalid certificate — icinga2 CWE-296 7.4AI High AI 2025-05-27
CVE-2024-49369 Icinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API Connections — icinga2 CWE-295 9.8 Critical 2024-11-12
CVE-2021-37698 Missing TLS service certificate validation in GelfWriter, ElasticsearchWriter, InfluxdbWriter and Influxdb2Writer — icinga2 CWE-295 7.5 High 2021-08-19
CVE-2021-32743 Passwords used to access external services inadvertently exposed through API — icinga2 CWE-202 8.8 High 2021-07-15
CVE-2021-32739 Results of queries for ApiListener objects include the ticket salt which allows in turn to steal (more privileged) identities — icinga2 CWE-267 8.8 High 2021-07-15

This page lists every published CVE security advisory associated with Icinga. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.