Input validation error in Icinga - CVE-2026-61552
Published: June 29, 2026 / Updated: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper input validation in the /v1/objects API endpoint when writing template names to generated configuration files. A remote privileged user can submit a specially crafted request to escalate privileges.
Exploitation is limited to API users with permission to create configuration objects.
Affected software
Debian Linux
icinga2 (Debian package)
How to mitigate CVE-2026-61552
icinga2 (Debian package) - update to 2.14.6-1+deb13u1