
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-61552 is a DSL injection vulnerability in Icinga 2 caused by unescaped import template names when creating configuration objects via the /v1/objects API endpoint. Affected versions span from 2.4 up to (but not including) 2.16.2, with patched versions available at 2.16.2, 2.15.4, and 2.14.9. The vulnerability carries a CVSS v3.1 base score of 7.2 (High) (Icinga Advisory). It was published on June 29, 2026, and was independently reported by multiple researchers (Icinga Advisory).
The root cause is insufficient input sanitization (improper neutralization of special elements) when template names supplied via the /v1/objects API endpoint are written directly into Icinga 2 configuration files. An authenticated API user with any objects/create/* permission can inject arbitrary Icinga 2 DSL (Domain Specific Language) configuration by crafting malicious template names, enabling privilege escalation within the monitoring environment. The attack vector is network-based, requires high privileges (a valid API user with object creation rights), and no user interaction (Icinga Advisory).
Successful exploitation allows an authenticated API user to inject arbitrary Icinga 2 configuration, leading to full compromise of confidentiality, integrity, and availability of the affected Icinga 2 instance. The attacker can escalate their privileges within the monitoring system, potentially gaining control over monitored hosts, check commands, and notification configurations. This could facilitate lateral movement within the monitored infrastructure by manipulating check scripts or notification handlers (Icinga Advisory).
Exploitation requires a valid Icinga 2 API user account with at least one objects/create/* permission, limiting the attack surface to authenticated users. No public proof-of-concept exploit code has been identified in the available sources, and there is no current evidence of in-the-wild exploitation. The vulnerability is detectable by Nessus (plugin 333603) and Qualys (detection ID 6285557) (Tenable). CISA KEV catalog status and EPSS score are not currently available for this CVE.
objects/create/* permission (e.g., objects/create/Service)./v1/objects/<type>/<name> endpoint, embedding a crafted template name containing Icinga 2 DSL syntax (e.g., newlines and additional configuration directives) in the templates array of the JSON body./v1/objects/ API endpoints from API users not typically performing object creation; API calls with abnormally long or specially formatted templates values./etc/icinga2/ or the zones.d directory) containing unexpected DSL directives, newline characters, or configuration blocks not matching normal administrative activity; newly created or modified .conf files with unusual content.Icinga has released patched versions 2.16.2, 2.15.4, and 2.14.9, which include fixes for this vulnerability; upgrading to one of these versions is the recommended remediation (Icinga Advisory). As an immediate workaround, administrators should remove objects/create/* permissions from all API users that do not strictly require them, as the vulnerability is only exploitable by users holding these permissions. Additionally, restricting API access to trusted IP ranges via firewall rules reduces the attack surface.
The vulnerability was covered by security aggregators including AusCERT (ESB-2026.9286) and Pro-Linux, and was picked up by Linux compatibility news outlets noting it as part of a broader Debian security update batch (AusCERT). The Icinga project acknowledged independent discovery by researchers TristanInSec and de3erve-hunter alongside their own internal identification, suggesting active community engagement with the issue (Icinga Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."