CVE-2026-61550: Icinga 2: Improper access control for JSON-RPC update certificate messages
Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker able to connect to TCP port 5665 can replace the node certificate and trusted CA certificate, impersonate a trusted node, and take control of the node. This issue is fixed in versions 2.14.9, 2.15.4, and 2.16.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Icinga 2to a version that resolves this vulnerability.Fixed in 2.14.9 - Upgrade
Upgrade
Icinga 2to a version that resolves this vulnerability.Fixed in 2.15.4 - Upgrade
Upgrade
Icinga 2to a version that resolves this vulnerability.Fixed in 2.16.2
Event History
Frequently Asked Questions
Which systems are exposed to remote exploitation?
Icinga 2 nodes running affected releases are exposed if an attacker can connect to TCP port 5665. The attacker does not need authentication or user interaction.
What access does an attacker gain after exploitation?
An attacker can replace the node certificate and trusted CA certificate, impersonate a trusted node, and take control of the affected node.
Which releases contain the fix?
The issue is fixed in Icinga 2 versions 2.14.9, 2.15.4, and 2.16.2. Affected versions begin with 2.8 and extend up to the fixed releases.