Improper access control in Icinga - #VU144223
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in /v1/events filter expressions when handling requests to the /v1/events API endpoint. A remote privileged user can send a specially crafted request containing filter expressions to disclose sensitive information.
Exploitation requires some events/* permission that allows access to the /v1/events API endpoint.