CVE-2025-61789Medium· 5.3▾ SunlitIcinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with access to Icinga DB Web, can use a custom variable in a filter that is either protected by icingadb/protect/variables or …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with access to Icinga DB Web, can use a custom variable in a filter that is either protected by icingadb/protect/variables or hidden by icingadb/denylist/variables, to guess values assigned to it. Versions 1.1.4 and 1.2.3 respond with an error if such a custom variable is used.
icinga_db_web < 1.1.4icinga_db_web >= 1.2.0, < 1.2.3Upgrade past the affected range:
icinga_db_web 1.2.3Connected by shared product, vendor, weakness, or advisory.
CVE-2025-61907Medium· 6.5Icinga 2 is an open source monitoring system
CVE-2025-61909Medium· 4.4Icinga 2 is an open source monitoring system
CVE-2025-61908Medium· 6.5Icinga 2 is an open source monitoring system
CVE-2026-61550Critical· 9.8Icinga 2 is an open source monitoring system
CVE-2026-61551High· 8.6Icinga 2 is an open source monitoring system
CVE-2026-61552High· 7.2Icinga 2 is an open source monitoring system