Description
Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker able to connect to TCP port 5665 can replace the node certificate and trusted CA certificate, impersonate a trusted node, and take control of the node. This issue is fixed in versions 2.14.9, 2.15.4, and 2.16.2.
Published: 2026-09-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Fix
AI Analysis

Impact

The vulnerability arises from improper access control in the JSON‑RPC certificate update messages. An unauthenticated attacker who can reach TCP port 5665 can send a crafted request that replaces the node certificate and trusted CA certificate. By doing so, the attacker can impersonate a trusted node, gain full control over the monitored node, and potentially execute arbitrary code, providing complete system compromise. This weakness is classified as CWE-862.

Affected Systems

Affected systems include the Icinga monitoring platform, specifically Icinga2. Versions from 2.8 up to 2.14.8 are vulnerable, and the issue has been fixed in releases 2.14.9, 2.15.4, and 2.16.2. These vulnerable releases lack proper validation when handling certificate update JSON‑RPC requests, allowing an attacker to replace node certificates and impersonate trusted nodes.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity. Since the EPSS score is not available, the risk remains high; attackers who can reach TCP port 5665 can exploit the vulnerability on vulnerable releases up to 2.14.8. The issue is not listed in CISA KEV catalog, but the high CVSS and the potential for complete node takeover warrant immediate attention. Network‑based attackers can execute the vulnerability without authentication, underscoring the need to close the exposure promptly.

Generated by OpenCVE AI on September 19, 2026 at 12:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Icinga2 to at least version 2.14.9, 2.15.4, or 2.16.2, or any later release that contains the fix.
  • Restrict access to TCP port 5665 so that only trusted hosts can reach the JSON‑RPC interface.
  • Enforce strict certificate validation so that only authenticated and trusted endpoints are allowed to update node certificates.

Generated by OpenCVE AI on September 19, 2026 at 12:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6426-1 icinga2 security update
History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker able to connect to TCP port 5665 can replace the node certificate and trusted CA certificate, impersonate a trusted node, and take control of the node. This issue is fixed in versions 2.14.9, 2.15.4, and 2.16.2.
Title Icinga 2: Improper access control for JSON-RPC update certificate messages
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T17:21:18.217Z

Reserved: 2026-07-10T16:48:39.922Z

Link: CVE-2026-61550

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-18T18:17:08.217

Modified: 2026-09-18T18:17:08.217

Link: CVE-2026-61550

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T12:30:17Z

Weaknesses