Vulnerability Description
Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier, the redfish-* plugins built request URLs by concatenating an operator-supplied base URL with response-supplied @odata.id links, allowing a malicious or compromised BMC to redirect authenticated Redfish requests and disclose X-Auth-Token or HTTP Basic credentials.
Related Weaknesses (CWE)
References
- https://github.com/Linuxfabrik/monitoring-plugins/commit/ffb0a81308cbfc018da857a
- https://github.com/Linuxfabrik/monitoring-plugins/security/advisories/GHSA-96fx-
FAQ
What is CVE-2026-67436?
CVE-2026-67436 is a documented vulnerability. Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier, the redfish-* plugins built request URLs by concatenating an...
How severe is CVE-2026-67436?
CVSS scoring is not yet available for CVE-2026-67436. Check NVD for updates.
Is there a patch for CVE-2026-67436?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.