Improper access control in Icinga - CVE-2021-32739
Published: July 15, 2021 / Updated: June 29, 2026
Icinga
Detailed vulnerability description
The vulnerability allows a remote user to steal more privileged identities.
The vulnerability exists due to improper access control in ApiListener object query results when handling API object queries. A remote user can query ApiListener objects to obtain the ticket salt and request a certificate for an arbitrary common name to steal more privileged identities.
Exploitation requires credentials for an API user with permission to query objects.