CVE-2026-24413Disclosure(icinga / icinga)

LOWCVSS 5.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prior to versions 2.13.14, 2.14.8, and 2.15.2, the Icinga 2 MSI did not set appropriate permissions for the `%ProgramData%\icinga2\var` folder on Windows. This resulted in the its contents - including the private key of the user and synced configuration - being readable by all local users. All installations on Windows are affected. Versions 2.13.14, 2.14.8, and 2.15.2 contains a fix. There are two possibilities to work around the issue without upgrading Icinga 2. Upgrade Icinga for Windows to at least version v1.13.4, v1.12.4, or v1.11.2. These version will automatically fix the ACLs for the Icinga 2 agent as well. Alternatively, manually update the ACL for the given folder `C:\ProgramData\icinga2\var` (and `C:\Program Files\WindowsPowerShell\modules\icinga-powershell-framework\certificate` to fix the issue for the Icinga for Windows as well) including every sub-folder and item to restrict access for general users, only allowing the Icinga service user and administrators access.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-276

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • icinga
  • windows

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
icingawindows

1 version affected across 2 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-01-29: 2Technical Details · 2026-01-29: 201-29
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24413 Local Privilege Escalation via Insecure Permissions in Icinga 2 Windows Installations https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24413

    Post summary

    The post announces a local privilege escalation vulnerability (CVE-2026-24413) affecting Icinga 2 Windows installations, noting insecure permissions, but does not provide PoC, exploit code, or patch details.

    0000047
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24413 Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prior to versions 2.13.14, 2.14.8, and 2.15.2, the Icinga 2 MSI did not set appropriate pe… https://www.cve.org/CVERecord?id=CVE-2026-24413

    Post summary

    The text announces a vulnerability in Icinga 2 where the MSI installer fails to set proper permissions, but it provides no PoC, exploit, or patch information.

    00000166
    56.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appicingaicinga---
OSmicrosoftwindows---

Explore more