Improper access control in Icinga - CVE-2026-61550
Published: June 29, 2026 / Updated: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to take control over the node.
The vulnerability exists due to improper access control in certificate update JSON-RPC message handling when processing certificate update messages. A remote attacker can send a specially crafted certificate update message to take control over the node.
An attacker can update both the node's own certificate and the trusted CA certificate, enabling impersonation of a trusted node.
Affected software
Debian Linux
icinga2 (Debian package)
How to mitigate CVE-2026-61550
icinga2 (Debian package) - update to 2.14.6-1+deb13u1