CVE-2026-24413
Icinga vulnerability analysis and mitigation

Overview

CVE-2026-24413 is an incorrect default permissions vulnerability in Icinga 2 on Windows that allows local users to read sensitive files including private keys and synced configuration. The Icinga 2 MSI installer fails to set appropriate ACLs on the %ProgramData%\icinga2\var folder, making its contents readable by all local users. The vulnerability affects Icinga 2 versions 2.3.0 through 2.13.13, 2.14.0 through 2.14.7, and 2.15.0 through 2.15.1 — all Windows installations are affected. It was published on January 29, 2026, with a CVSS v3.1 score of 5.5 (Medium) and a CVSS v4.0 score of 6.8 (Medium) (GitHub Advisory, Feedly).

Technical details

The root cause is CWE-276 (Incorrect Default Permissions): the Icinga 2 MSI installer does not configure restrictive ACLs on C:\ProgramData\icinga2\var during installation, leaving the directory and all its contents world-readable by any local user. An attacker with a low-privileged local account can simply browse or read files within this directory — no special tools or techniques are required. The exposed contents include the Icinga agent's private TLS key and synced monitoring configuration files. A related issue in the Icinga for Windows PowerShell framework (CVE-2026-24414, GHSA-88h5-rrm6-5973) similarly exposes certificates under C:\Program Files\WindowsPowerShell\modules\icinga-powershell-framework\certificate (GitHub Advisory, PS Framework Advisory).

Impact

Successful exploitation allows any local user on an affected Windows system to read the Icinga 2 agent's private TLS key and synced monitoring configuration. Exposure of the private key could enable an attacker to impersonate the Icinga agent, intercept or tamper with monitoring communications, or potentially pivot to other systems within the Icinga monitoring infrastructure. There is no direct integrity or availability impact, but the stolen cryptographic material could facilitate further attacks against the broader monitoring environment (GitHub Advisory, Feedly).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.007% (very low probability of exploitation in the near term). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires only a low-privileged local account on an affected Windows system, making it trivially simple for any local user to attempt (Feedly, GitHub Advisory).

Exploitation steps

  1. Gain local access: Obtain any low-privileged local user account on a Windows system running Icinga 2 versions 2.3.0–2.15.1.
  2. Locate the vulnerable directory: Navigate to C:\ProgramData\icinga2\var using Windows Explorer or a command prompt (e.g., dir C:\ProgramData\icinga2\var).
  3. Read private key material: Access and copy the Icinga agent's private TLS key file stored within the directory (e.g., using type or copy commands, or any file manager).
  4. Read synced configuration: Similarly read any synced monitoring configuration files present in the directory to understand the monitoring topology and credentials.
  5. Leverage stolen material: Use the extracted private key to impersonate the Icinga agent in TLS communications, potentially enabling man-in-the-middle attacks against the Icinga monitoring infrastructure or unauthorized access to monitored systems (GitHub Advisory).

Indicators of compromise

  • File System: Unexpected access timestamps on files within C:\ProgramData\icinga2\var and its subdirectories, particularly on private key files (.key or .pem files); similar anomalies under C:\Program Files\WindowsPowerShell\modules\icinga-powershell-framework\certificate.
  • Logs: Windows Security Event Log entries (Event ID 4663) showing file read access to C:\ProgramData\icinga2\var by non-Icinga service accounts or non-administrator users.
  • Process: Unexpected processes (e.g., cmd.exe, powershell.exe, file manager processes) accessing the Icinga data directory under a non-service user context.

Mitigation and workarounds

Upgrade Icinga 2 to one of the patched versions: 2.13.14, 2.14.8, or 2.15.2, which set correct ACLs during installation. Alternatively, upgrade Icinga for Windows to at least v1.13.4, v1.12.4, or v1.11.2 — these versions automatically fix the ACLs for the Icinga 2 agent as well. If immediate upgrading is not possible, manually restrict the ACL on C:\ProgramData\icinga2\var (and C:\Program Files\WindowsPowerShell\modules\icinga-powershell-framework\certificate for Icinga for Windows) to allow access only to the Icinga service user and administrators, applying the restriction recursively to all sub-folders and files (GitHub Advisory, Icinga Blog).

Community reactions

The vulnerability was disclosed by Icinga maintainer julianbrost via GitHub Security Advisories on January 29, 2026, alongside a coordinated release of patched versions and a companion advisory for the Icinga for Windows PowerShell framework (GHSA-88h5-rrm6-5973). The Icinga project published a blog post announcing the simultaneous release of fixed versions for both Icinga 2 and Icinga for Windows. No significant broader media coverage or notable external researcher commentary has been identified beyond standard vulnerability database aggregation (GitHub Advisory, Icinga Blog).

Additional resources


SourceThis report was generated using AI

Related Icinga vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-24413MEDIUM6.8
  • Icinga logoIcinga
  • cpe:2.3:a:icinga:icinga
NoYesJan 29, 2026
CVE-2025-61909MEDIUM4
  • Icinga logoIcinga
  • icinga2
NoYesOct 16, 2025
CVE-2026-61552NONEN/A
  • Icinga logoIcinga
  • icinga2
NoYesAug 13, 2026
CVE-2026-61551NONEN/A
  • Icinga logoIcinga
  • icinga2
NoYesAug 13, 2026
CVE-2026-61550NONEN/A
  • Icinga logoIcinga
  • icinga2
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management