Input validation error in Icinga - #VU135837
Published: June 29, 2026
Icinga
Detailed vulnerability description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper input validation in the /v1/objects API endpoint when writing template names to generated configuration files. A remote privileged user can submit a specially crafted request to escalate privileges.
Exploitation is limited to API users with permission to create configuration objects.