Vulnerability Description
Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes attacker-controlled template names into generated configuration without escaping them. An authenticated ApiUser with an objects/create/* permission can inject Icinga 2 DSL configuration, escape the intended object, create additional objects, and exceed the user's assigned privileges. This issue is fixed in versions 2.14.9, 2.15.4, and 2.16.2.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/Icinga/icinga2/commit/125b7734e84d03f09b79d36c270152b11629a8c
- https://github.com/Icinga/icinga2/commit/af4b36e6464b9b214bed270a53d6474cf91eb44
- https://github.com/Icinga/icinga2/commit/eec0d90e8303376fe772b3e4a04e3b064a44cf3
- https://github.com/Icinga/icinga2/commit/faf0450962ad678397991cfdf041810feafa71e
- https://github.com/Icinga/icinga2/pull/10910
- https://github.com/Icinga/icinga2/releases/tag/v2.14.9
- https://github.com/Icinga/icinga2/releases/tag/v2.15.4
- https://github.com/Icinga/icinga2/releases/tag/v2.16.2
- https://github.com/Icinga/icinga2/security/advisories/GHSA-jgqj-x5j9-vgcm
- https://icinga.com/blog/icinga2-security-release-v2-16-2
FAQ
What is CVE-2026-61552?
CVE-2026-61552 is a vulnerability with a CVSS score of 7.2 (HIGH). Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes attacker-controlled template names into generated configuration without escaping the...
How severe is CVE-2026-61552?
CVE-2026-61552 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-61552?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.