CVE-2026-61551
Icinga vulnerability analysis and mitigation

Overview

CVE-2026-61551 is a stack overflow vulnerability in Icinga 2 triggered by sending crafted deeply nested JSON objects. It affects Icinga 2 versions prior to 2.16.2, 2.15.4, and 2.14.9, and is also present in Debian Linux systems running the Icinga 2 package. The vulnerability was published on June 29, 2026, and carries a CVSS v3.1 base score of 8.6 (High) (Icinga Advisory). Debian-specific packaging is tracked separately, with Feedly noting the vendor indicated no patch was available at the time of initial detection (Feedly).

Technical details

The root cause is improper handling of deeply nested JSON structures during parsing, which exhausts the call stack and causes a stack overflow (consistent with CWE-674: Uncontrolled Recursion). The vulnerable code path is reachable by unauthenticated clients over the network via TCP port 5665, requiring no privileges or user interaction. While the primary demonstrated impact is a crash of the Icinga 2 process, the advisory notes that code execution cannot be ruled out due to the nature of stack overflows (Icinga Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to crash the Icinga 2 monitoring process, resulting in a denial of service for the monitoring infrastructure. Any Icinga 2 instance accessible over the network is affected, potentially blinding operators to alerts and system health events. Additionally, the possibility of remote code execution — which would compromise confidentiality and integrity — has not been ruled out by the vendor (Icinga Advisory).

Exploitability

The vulnerability is exploitable by unauthenticated attackers with network access to TCP port 5665, requiring low attack complexity and no user interaction. Detection plugins for Nessus (ID: 333603) and Qualys (ID: 6285443) have been published, indicating active scanner coverage (Feedly). No confirmed in-the-wild exploitation, threat actor attribution, or CISA KEV listing has been reported as of the available data. EPSS score data is not yet available given the recent reservation status of the CVE.

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible Icinga 2 instances using tools like Shodan or Censys, targeting TCP port 5665 on systems running Icinga 2 versions prior to 2.16.2, 2.15.4, or 2.14.9.
  2. Craft malicious payload: Construct a JSON object with deeply nested structures (e.g., hundreds or thousands of levels of nested arrays or objects) designed to exhaust the JSON parser's call stack.
  3. Send crafted request: Transmit the malicious JSON payload to the Icinga 2 API endpoint on TCP port 5665 without any authentication credentials.
  4. Trigger stack overflow: The Icinga 2 process attempts to parse the deeply nested JSON, recursively consuming stack frames until a stack overflow occurs, crashing the process.
  5. Achieve objective: At minimum, the Icinga 2 monitoring daemon crashes (denial of service); depending on memory layout and platform, further exploitation for code execution may be possible (Icinga Advisory).

Indicators of compromise

  • Network: Unexpected or repeated connection attempts to TCP port 5665 from untrusted or external IP addresses; large or malformed JSON payloads in network captures destined for Icinga 2.
  • Logs: Icinga 2 process crash logs or segmentation fault entries in system logs (e.g., /var/log/syslog, /var/log/icinga2/icinga2.log); repeated process restarts logged by systemd or init.
  • Process: Sudden termination of the icinga2 daemon process; watchdog or supervisor processes restarting Icinga 2 unexpectedly.
  • File System: Core dump files generated in the Icinga 2 working directory following a crash event (Icinga Advisory).

Mitigation and workarounds

Icinga 2 has released patched versions v2.16.2, v2.15.4, and v2.14.9, which include fixes for this vulnerability; upgrading to one of these versions is the recommended remediation (Icinga Advisory). There is no in-application workaround available. As a network-level mitigation, restrict access to TCP port 5665 using firewall rules so that only trusted hosts can communicate with the Icinga 2 instance. Debian users should monitor their distribution's security tracker for updated packages, as Feedly noted the vendor had not yet published a Debian-specific patch at initial disclosure (Feedly).

Community reactions

The vulnerability received coverage from the German Linux security news site Pro-Linux.de and was picked up by AUSCERT (bulletin ESB-2026.9286) and LinuxCompatible.org as part of broader Debian security update roundups (Feedly). Tenable published a Nessus detection plugin (ID 333603) shortly after disclosure, indicating prompt response from the vulnerability scanning community. No notable individual researcher commentary or significant social media discussion has been identified beyond standard security advisory distribution.

Additional resources


SourceThis report was generated using AI

Related Icinga vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-24413MEDIUM6.8
  • Icinga logoIcinga
  • cpe:2.3:a:icinga:icinga
NoYesJan 29, 2026
CVE-2025-61909MEDIUM4
  • Icinga logoIcinga
  • icinga2
NoYesOct 16, 2025
CVE-2026-61552NONEN/A
  • Icinga logoIcinga
  • icinga2
NoYesAug 13, 2026
CVE-2026-61551NONEN/A
  • Icinga logoIcinga
  • icinga2
NoYesAug 13, 2026
CVE-2026-61550NONEN/A
  • Icinga logoIcinga
  • icinga2
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management