critical · CVSS v3 9.8
CVE-2026-61550
Icinga 2 certificate update JSON‑RPC handling fails to verify the sender, allowing an unauthenticated attacker on TCP port 5665 to replace n
Overview
Icinga 2 certificate update JSON‑RPC handling fails to verify the sender, allowing an unauthenticated attacker on TCP port 5665 to replace node and CA certificates. This lets the attacker impersonate a trusted node and take full control of the monitored system. The flaw is present in versions 2.8 through 2.14.9, 2.15.4, and 2.16.2.
Description
Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker able to connect to TCP port 5665 can replace the node certificate and trusted CA certificate, impersonate a trusted node, and take control of the node. This issue is fixed in versions 2.14.9, 2.15.4, and 2.16.2.
Impact
Confidentiality: attacker can read monitoring data; Integrity: attacker can alter monitoring configuration and inject false alerts; Availability: attacker can disrupt monitoring services by replacing certificates. System administrators and network operators are directly impacted.
Remediation
Apply the latest patch that includes the fix (2.14.9, 2.15.4, or 2.16.2). If patching is not immediately possible, restrict TCP port 5665 to trusted IPs using firewall rules or disable JSON‑RPC certificate updates. Verify that only authorized endpoints can send certificate updates and monitor logs for unexpected certificate changes.
Risk context
The CVE has a critical severity score of 9.8, indicating a high likelihood of exploitation and significant impact. Immediate remediation is advised to prevent potential takeover of monitoring nodes.
Affected products
- Icinga 2 2.8-2.14.9
- Icinga 2 2.15.4
- Icinga 2 2.16.2
Scores
- Severity
- critical
- CVSS v2
- 10
- CVSS v3
- 9.8
- CVSS v4
- —
- EPSS
- —