CVE-2025-61909Medium· 4.4▾ SunlitIcinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, the safe-reload script (also used during systemctl reload icinga2) and logrotate configuration shipped with Icinga 2 read the PID of the mai…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 24.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, the safe-reload script (also used during systemctl reload icinga2) and logrotate configuration shipped with Icinga 2 read the PID of the main Icinga 2 process from a PID file writable by the daemon user, but send the signal as the root user. This can allow the Icinga user to send signals to processes it would otherwise not permitted to. A fix is included in the following Icinga 2 versions: 2.15.1, 2.14.7, and 2.13.13.
icinga >= 2.10.0, < 2.13.13icinga >= 2.14.0, < 2.14.7icinga = 2.15.0Upgrade past the affected range:
icinga 2.14.7Connected by shared product, vendor, weakness, or advisory.
CVE-2025-61908Medium· 6.5Icinga 2 is an open source monitoring system
CVE-2025-61907Medium· 6.5Icinga 2 is an open source monitoring system
CVE-2026-12505High· 7.8A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment
CVE-2025-61789Medium· 5.3Icinga DB Web provides a graphical interface for Icinga monitoring
CVE-2026-61550Critical· 9.8Icinga 2 is an open source monitoring system
CVE-2026-61551High· 8.6Icinga 2 is an open source monitoring system