CVE-2025-61907Medium· 6.5▾ SunlitIcinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to the various /v1/objects endpoints could access variables or objects that would otherwise be inaccessible for the user. …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to the various /v1/objects endpoints could access variables or objects that would otherwise be inaccessible for the user. This allows authenticated API users to learn information that should be hidden from them, including global variables not permitted by the variables permission and objects not permitted by the corresponding objects/query permissions. The vulnerability is fixed in versions 2.15.1, 2.14.7, and 2.13.13.
icinga >= 2.4.0, < 2.13.13icinga >= 2.14.0, < 2.14.7icinga = 2.15.0Upgrade past the affected range:
icinga 2.14.7Connected by shared product, vendor, weakness, or advisory.
CVE-2025-61909Medium· 4.4Icinga 2 is an open source monitoring system
CVE-2025-61908Medium· 6.5Icinga 2 is an open source monitoring system
CVE-2025-61789Medium· 5.3Icinga DB Web provides a graphical interface for Icinga monitoring
CVE-2020-17527High· 7.5While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the…
CVE-2022-31746Medium· 6.5Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header
CVE-2026-61550Critical· 9.8Icinga 2 is an open source monitoring system