Severity
7.1HIGHNVD
EPSS
0.0%
top 87.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 16

Description

Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to the various /v1/objects endpoints could access variables or objects that would otherwise be inaccessible for the user. This allows authenticated API users to learn information that should be hidden from them, including global variables not permitted by the variables permission and objects not permitted by the corresponding objects/query permissions. The vulnerability is fixed in

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N

Affected Packages3 packages

NVDicinga/icinga2.4.02.13.13+2
Debianicinga/icinga2< 2.15.1-1
CVEListV5icinga/icinga2>= 2.14.0, < 2.14.7, >= 2.15.0, < 2.15.1, >= 2.4.0, < 2.13.13+2

Patches

🔴Vulnerability Details

2
OSV
CVE-2025-61907: Icinga 2 is an open source monitoring system2025-10-16
CVEList
Icinga 2 API users could access restricted values in filter expressions2025-10-16

📋Vendor Advisories

1
Debian
CVE-2025-61907: icinga2 - Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2...2025
CVE-2025-61907 — Sensitive Information Exposure | cvebase