CVE-2026-24414 Details
Description
The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of Windows environments. In versions prior to 1.13.4, 1.12.4, and 1.11.2, permissions of the Icinga for Windows `certificate` directory grant every user read access, which results in the exposure of private key of the Icinga certificate for the given host. All installations are affected. Versions 1.13.4, 1.12.4, and 1.11.2 contains a patch. Please note that upgrading to a fixed version of Icinga for Windows will also automatically fix a similar issue present in Icinga 2, CVE-2026-24413. As a workaround, the permissions can be restricted manually by updating the ACL for the given folder `C:\Program Files\WindowsPowerShell\modules\icinga-powershell-framework\certificate` (and `C:\ProgramData\icinga2\var` to fix the issue for the Icinga 2 agent as well) including every sub-folder and item to restrict access for general users, only allowing the Icinga service user and administrators access.
A vulnerability exists in Icinga for Windows versions prior to 1.13.4, 1.12.4, and 1.11.2, as well as in Icinga 2 versions 2.3 through 2.15.1. The issue arises because the 'certificate' directory in Icinga for Windows and the 'var' directory in Icinga 2 on Windows do not have proper permissions set. This oversight allows all local users to read sensitive contents, including private keys and configuration data. All installations on Windows are affected.
Users can manually update the Access Control List (ACL) for the affected directories to restrict access for general users, allowing only the Icinga service user and administrators to access them. Alternatively, Icinga for Windows can be upgraded to version 1.13.4, 1.12.4, or 1.11.2, which will automatically fix the permission issue for the Icinga 2 agent as well. Icinga 2 can be upgraded to version 2.15.2, 2.14.8, or 2.13.14.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-276 | Incorrect Default Permissions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| icinga icinga powershell framework | < 1.11.2 >= 1.12.0, < 1.12.4 >= 1.13.0, < 1.13.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 10, 2026 | Initial Analysis | [email protected] |
| Jan 29, 2026 | New CVE Received | [email protected] |