CVE-2026-24414Disclosure(icinga / icinga_powershell_framework)

LOWCVSS 5.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of Windows environments. In versions prior to 1.13.4, 1.12.4, and 1.11.2, permissions of the Icinga for Windows `certificate` directory grant every user read access, which results in the exposure of private key of the Icinga certificate for the given host. All installations are affected. Versions 1.13.4, 1.12.4, and 1.11.2 contains a patch. Please note that upgrading to a fixed version of Icinga for Windows will also automatically fix a similar issue present in Icinga 2, CVE-2026-24413. As a workaround, the permissions can be restricted manually by updating the ACL for the given folder `C:\Program Files\WindowsPowerShell\modules\icinga-powershell-framework\certificate` (and `C:\ProgramData\icinga2\var` to fix the issue for the Icinga 2 agent as well) including every sub-folder and item to restrict access for general users, only allowing the Icinga service user and administrators access.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-276

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • icinga_powershell_framework

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
icinga_powershell_framework

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-01-29: 2Technical Details · 2026-01-29: 101-29
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24414 Certificate Directory Permission Vulnerability in Icinga PowerShell Framework https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24414

    Post summary

    The post announces a certificate directory permission flaw in the Icinga PowerShell Framework (CVE-2026-24414), without any PoC, exploit, mitigation, or active exploitation details.

    0000042
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-24414 The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of Windows environments. In versions prior to 1.13… https://www.cve.org/CVERecord?id=CVE-2026-24414

    Post summary

    The text only references CVE‑2026‑24414 as affecting Icinga PowerShell Framework versions before 1.13, providing no further technical or exploit details.

    00000154
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appicingaicinga_powershell_framework---

Explore more