CVE-2025-61907: Icinga 2 API users could access restricted values in filter expressions
Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to the various /v1/objects endpoints could access variables or objects that would otherwise be inaccessible for the user. This allows authenticated API users to learn information that should be hidden from them, including global variables not permitted by the variables permission and objects not permitted by the corresponding objects/query permissions. The vulnerability is fixed in versions 2.15.1, 2.14.7, and 2.13.13.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61907?
CVE-2025-61907 has been classified as a medium severity vulnerability.
How do I fix CVE-2025-61907?
To fix CVE-2025-61907, upgrade Icinga 2 to version 2.15.1 or later.
What versions of Icinga 2 are affected by CVE-2025-61907?
Icinga 2 versions 2.4 through 2.15.0 are affected by CVE-2025-61907.
What type of vulnerability is CVE-2025-61907?
CVE-2025-61907 is an authorization issue that allows authenticated users to access restricted variables or objects.
Who is the vendor for CVE-2025-61907?
The vendor for CVE-2025-61907 is Icinga, the creator of the Icinga 2 monitoring system.