CVE-2026-24414: Icinga for Windows certificate can have too-open permissions

Published Jan 29, 2026
·
Updated

The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of Windows environments. In versions prior to 1.13.4, 1.12.4, and 1.11.2, permissions of the Icinga for Windows certificate directory grant every user read access, which results in the exposure of private key of the Icinga certificate for the given host. All installations are affected. Versions 1.13.4, 1.12.4, and 1.11.2 contains a patch. Please note that upgrading to a fixed version of Icinga for Windows will also automatically fix a similar issue present in Icinga 2, CVE-2026-24413. As a workaround, the permissions can be restricted manually by updating the ACL for the given folder C:\Program Files\WindowsPowerShell\modules\icinga-powershell-framework\certificate (and C:\ProgramData\icinga2\var to fix the issue for the Icinga 2 agent as well) including every sub-folder and item to restrict access for general users, only allowing the Icinga service user and administrators access.

Affected Software

4 affected components
Icinga Icinga for Windows<1.11.2, <1.12.4, <1.13.4
Icinga Icinga PowerShell Framework<1.11.2
Icinga Icinga PowerShell Framework>=1.12.0<1.12.4
Icinga Icinga PowerShell Framework>=1.13.0<1.13.4

Event History

Jan 29, 2026
CVE Published
via MITRE·05:35 PM
Data Sourced
via MITRE·05:35 PM
DescriptionWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-24414?

CVE-2026-24414 has been classified as a medium severity vulnerability due to its implications on permissions.

2

How do I fix CVE-2026-24414?

To fix CVE-2026-24414, you need to upgrade to Icinga for Windows version 1.13.4, 1.12.4, or 1.11.2.

3

Who is affected by CVE-2026-24414?

CVE-2026-24414 affects users of Icinga for Windows running versions prior to 1.13.4, 1.12.4, and 1.11.2.

4

What are the potential risks of CVE-2026-24414?

The potential risks of CVE-2026-24414 include unauthorized access due to too-open permissions on certificates.

5

Is there a workaround for CVE-2026-24414?

No official workaround is recommended for CVE-2026-24414; upgrading to the fixed versions is the suggested solution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203