CVE-2026-24413 Details
Description
Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prior to versions 2.13.14, 2.14.8, and 2.15.2, the Icinga 2 MSI did not set appropriate permissions for the `%ProgramData%\icinga2\var` folder on Windows. This resulted in the its contents - including the private key of the user and synced configuration - being readable by all local users. All installations on Windows are affected. Versions 2.13.14, 2.14.8, and 2.15.2 contains a fix. There are two possibilities to work around the issue without upgrading Icinga 2. Upgrade Icinga for Windows to at least version v1.13.4, v1.12.4, or v1.11.2. These version will automatically fix the ACLs for the Icinga 2 agent as well. Alternatively, manually update the ACL for the given folder `C:\ProgramData\icinga2\var` (and `C:\Program Files\WindowsPowerShell\modules\icinga-powershell-framework\certificate` to fix the issue for the Icinga for Windows as well) including every sub-folder and item to restrict access for general users, only allowing the Icinga service user and administrators access.
A vulnerability exists in Icinga 2 versions 2.3.0 through 2.15.1 and in Icinga for Windows versions prior to 1.13.4, 1.12.4, and 1.11.2. The issue arises because the Icinga 2 MSI package did not apply the correct permissions to the '%ProgramData%\icinga2\var' directory on Windows. As a result, the folder's contents, which include the user's private key and synchronized configuration, were accessible to all local users. This vulnerability affects all Windows installations of Icinga 2.
Users can upgrade Icinga 2 to versions 2.15.2, 2.14.8, or 2.13.14. For Icinga for Windows, versions 1.13.4, 1.12.4, or 1.11.2 should be installed. If an upgrade is not possible, the permissions can be manually adjusted to restrict access for general users, allowing only the Icinga service user and administrators to access the folders.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-276 | Incorrect Default Permissions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| icinga icinga | >= 2.3.0, < 2.13.14 >= 2.14.0, < 2.14.8 >= 2.15.0, < 2.15.2 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 19, 2026 | Initial Analysis | [email protected] |
| Jan 29, 2026 | New CVE Received | [email protected] |