
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24413 is an incorrect default permissions vulnerability in Icinga 2 on Windows that allows local users to read sensitive files including private keys and synced configuration. The Icinga 2 MSI installer fails to set appropriate ACLs on the %ProgramData%\icinga2\var folder, making its contents readable by all local users. The vulnerability affects Icinga 2 versions 2.3.0 through 2.13.13, 2.14.0 through 2.14.7, and 2.15.0 through 2.15.1 — all Windows installations are affected. It was published on January 29, 2026, with a CVSS v3.1 score of 5.5 (Medium) and a CVSS v4.0 score of 6.8 (Medium) (GitHub Advisory, Feedly).
The root cause is CWE-276 (Incorrect Default Permissions): the Icinga 2 MSI installer does not configure restrictive ACLs on C:\ProgramData\icinga2\var during installation, leaving the directory and all its contents world-readable by any local user. An attacker with a low-privileged local account can simply browse or read files within this directory — no special tools or techniques are required. The exposed contents include the Icinga agent's private TLS key and synced monitoring configuration files. A related issue in the Icinga for Windows PowerShell framework (CVE-2026-24414, GHSA-88h5-rrm6-5973) similarly exposes certificates under C:\Program Files\WindowsPowerShell\modules\icinga-powershell-framework\certificate (GitHub Advisory, PS Framework Advisory).
Successful exploitation allows any local user on an affected Windows system to read the Icinga 2 agent's private TLS key and synced monitoring configuration. Exposure of the private key could enable an attacker to impersonate the Icinga agent, intercept or tamper with monitoring communications, or potentially pivot to other systems within the Icinga monitoring infrastructure. There is no direct integrity or availability impact, but the stolen cryptographic material could facilitate further attacks against the broader monitoring environment (GitHub Advisory, Feedly).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.007% (very low probability of exploitation in the near term). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires only a low-privileged local account on an affected Windows system, making it trivially simple for any local user to attempt (Feedly, GitHub Advisory).
C:\ProgramData\icinga2\var using Windows Explorer or a command prompt (e.g., dir C:\ProgramData\icinga2\var).type or copy commands, or any file manager).C:\ProgramData\icinga2\var and its subdirectories, particularly on private key files (.key or .pem files); similar anomalies under C:\Program Files\WindowsPowerShell\modules\icinga-powershell-framework\certificate.C:\ProgramData\icinga2\var by non-Icinga service accounts or non-administrator users.cmd.exe, powershell.exe, file manager processes) accessing the Icinga data directory under a non-service user context.Upgrade Icinga 2 to one of the patched versions: 2.13.14, 2.14.8, or 2.15.2, which set correct ACLs during installation. Alternatively, upgrade Icinga for Windows to at least v1.13.4, v1.12.4, or v1.11.2 — these versions automatically fix the ACLs for the Icinga 2 agent as well. If immediate upgrading is not possible, manually restrict the ACL on C:\ProgramData\icinga2\var (and C:\Program Files\WindowsPowerShell\modules\icinga-powershell-framework\certificate for Icinga for Windows) to allow access only to the Icinga service user and administrators, applying the restriction recursively to all sub-folders and files (GitHub Advisory, Icinga Blog).
The vulnerability was disclosed by Icinga maintainer julianbrost via GitHub Security Advisories on January 29, 2026, alongside a coordinated release of patched versions and a companion advisory for the Icinga for Windows PowerShell framework (GHSA-88h5-rrm6-5973). The Icinga project published a blog post announcing the simultaneous release of fixed versions for both Icinga 2 and Icinga for Windows. No significant broader media coverage or notable external researcher commentary has been identified beyond standard vulnerability database aggregation (GitHub Advisory, Icinga Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."