Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-61550

Icinga 2 JSON-RPC endpoint skips sender validation, allows node injection

Unauthenticated attacker can inject a malicious node into an Icinga 2 cluster by spoofing certificate update JSON-RPC messages. CVSS 9.8 critical. Fixed in 2.14.9, 2.15.4, 2.16.2.

cat cve-2026-61550.json
Vendor
Icinga
Product
Icinga 2
CVSS
9.8
EPSS (exploit probability)
0.4%
Status
patched
Published

Icinga 2’s JSON-RPC message handling for certificate updates does not verify that the sender is a trusted cluster endpoint. From version 2.8 through 2.14.8, 2.15.3, and 2.16.1, an unauthenticated remote attacker can send crafted certificate update messages to force Icinga 2 to accept a malicious node as trusted, compromising cluster integrity.

Fixed in Icinga 2.14.9, 2.15.4, and 2.16.2. No workaround is documented. Upgrade immediately; this is an unauthenticated cluster takeover path.

See NVD and the Icinga 2 GitHub advisory for version details.