---
id: CVE-2026-73973
title: >-
  Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios,
  and related systems
summary: >-
  Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios,
  and related systems. Prior to version 7.0.0, check-plugins/logfile/logfile
  accepted a free-form --filename path and opened it as root when invoked
  through the…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
  - CWE-269
published: '2026-08-18'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T21:13:25.910'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73973'
references:
  - url: >-
      https://github.com/Linuxfabrik/monitoring-plugins/blob/ae486fc629e1ca9373e1b6dd5e395603ee453bbc/CHANGELOG.md#v700---2026-08-14
    label: security-advisories@github.com
  - url: >-
      https://github.com/Linuxfabrik/monitoring-plugins/commit/a0ca1268d84e0caf10442b9c7477d699b52d1c92
    label: security-advisories@github.com
  - url: 'https://github.com/Linuxfabrik/monitoring-plugins/releases/tag/v7.0.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/Linuxfabrik/monitoring-plugins/security/advisories/GHSA-f54c-p5vg-mr5c
    label: security-advisories@github.com
  - url: >-
      https://github.com/Linuxfabrik/monitoring-plugins/security/advisories/GHSA-f54c-p5vg-mr5c
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00286
epssPercentile: 0.18886
ingestedAt: '2026-09-09T21:22:45.538Z'
---

## Overview

Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0.0, check-plugins/logfile/logfile accepted a free-form --filename path and opened it as root when invoked through the shipped nagios or icinga sudoers allowlist, without confining the resolved path to /var/log. An attacker who controls the monitoring account can select a root-readable file such as /etc/shadow and use --warning-regex . while leaving SUPPRESS_OUTPUT false, causing each nonempty line to be collected in warn_matches and returned through lib.base.oao(). The vulnerable flow passes the expanded scan_path directly to open(), and neither real-path containment nor an allowlist protects the sink. The same fix also confines mysql-logfile and openvpn-client-list paths, allows only documented log roots, and resolves symlinks and parent-directory traversal before checking containment. This issue is fixed in version 7.0.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
