PT-2026-5317 · Unknown+1 · Icinga For Windows+1

Julianbrost

·

Published

2026-01-29

·

Updated

2026-02-19

·

CVE-2026-24413

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Icinga 2 versions 2.3.0 through 2.13.14 Icinga 2 versions 2.3.0 through 2.14.8 Icinga 2 versions 2.3.0 through 2.15.2
Description Icinga 2 is an open source monitoring system. The MSI installer did not configure appropriate permissions for the %ProgramData%icinga2var folder on Windows systems. This allowed all local users to read the folder's contents, including the private key of the user and synced configuration. All installations on Windows are affected.
Recommendations Icinga 2 versions prior to 2.13.14 should be upgraded. Icinga 2 versions prior to 2.14.8 should be upgraded. Icinga 2 versions prior to 2.15.2 should be upgraded. Upgrade Icinga for Windows to at least version v1.13.4. Upgrade Icinga for Windows to at least version v1.12.4. Upgrade Icinga for Windows to at least version v1.11.2. Manually update the ACL for the folder C:ProgramDataicinga2var (and C:Program FilesWindowsPowerShellmodulesicinga-powershell-frameworkcertificate) including every sub-folder and item to restrict access for general users, only allowing the Icinga service user and administrators access.

Exploit

Fix

LPE

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2026-24413
GHSA-88H5-RRM6-5973
GHSA-VFJG-6FPV-4MMR
OPENSUSE-SU-2026:10113-1

Affected Products

Icinga 2
Icinga For Windows