Impact
This vulnerability stems from the Icinga 2 DSL injection flaw that occurs when the /v1/objects API writes attacker‑controlled template names into the generated configuration without properly escaping them. An authenticated ApiUser with objects/create/* permission can exploit this to inject arbitrary Icinga 2 DSL configuration, escape out of the intended object context, and create additional objects. The injected configuration can grant the attacker privileges that exceed the user’s assigned permissions, allowing manipulation of the monitoring system’s configuration in ways a legitimate user should not be able to.
Affected Systems
Affected systems include the Icinga open‑source monitoring platform. Vulnerable versions are 2.4 through 2.16.1, excluding the patched releases 2.14.9, 2.15.4, and 2.16.2. The issue is fixed in those releases, which sanitize template names before use.
Risk and Exploitability
The risk is rated moderate‑high with a CVSS base score of 7.2. The EPSS score is not available, so the current exploitation probability is unknown, yet the flaw is not yet listed in the CISA KEV catalog. The primary attack vector is through an authenticated API session; the attacker requires objects/create/* permissions but can then elevate privileges by injecting arbitrary configuration. Once exploited, the attacker could create objects that grant higher privileges or otherwise subvert the monitoring system, affecting configuration integrity and potentially leading to broader compromise of managed hosts.
OpenCVE Enrichment
Debian DSA