logo

Icinga 2 Vulnerabilities Allow Unauthenticated Node Takeover

ID: 986c5732-de90-5367-87b5-1059bcd106a8

STIX ID: report--986c5732-de90-5367-87b5-1059bcd106a8

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-07-03

Date Updated: 2026-08-06

Author: Do Son

ADMIRALTY:B6
...
...

Icinga 2 released fixes for three critical vulnerabilities (an unauthenticated certificate takeover allowing node/CA replacement, an unauthenticated stack overflow that can crash the service, and an authenticated DSL injection via the /v1/objects API) affecting releases prior to v2.16.2/v2.15.4/v2.14.9; administrators are advised to upgrade immediately, restrict TCP/5665 access, and remove objects/create rights from untrusted API users — no active exploitation has been confirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.