Improper access control in Icinga - #VU135839
Published: June 29, 2026
Icinga
Detailed vulnerability description
The vulnerability allows a remote attacker to take control over the node.
The vulnerability exists due to improper access control in certificate update JSON-RPC message handling when processing certificate update messages. A remote attacker can send a specially crafted certificate update message to take control over the node.
An attacker can update both the node's own certificate and the trusted CA certificate, enabling impersonation of a trusted node.