CVE-2026-24413Incorrect Default Permissions in Icinga-powershell-framework

Severity
6.8MEDIUMNVD
EPSS
0.0%
top 99.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 29

Description

Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prior to versions 2.13.14, 2.14.8, and 2.15.2, the Icinga 2 MSI did not set appropriate permissions for the `%ProgramData%\icinga2\var` folder on Windows. This resulted in the its contents - including the private key of the user and synced configuration - being readable by all local users. All installations on Windows are affected. Versions 2.13.14, 2.14.8, and 2.15.2 contains a fix. There are two possibilities to work a

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Packages3 packages

NVDicinga/icinga2.3.02.13.14+2
CVEListV5icinga/icinga2>= 2.14.0, < 2.14.8, >= 2.15.0, < 2.15.2, >= 2.3.0, < 2.13.14+2

Patches

🔴Vulnerability Details

2
CVEList
Icinga has insecure permission of %ProgramData%\icinga2\var on Windows2026-01-29
OSV
CVE-2026-24413: Icinga 2 is an open source monitoring system2026-01-29

📋Vendor Advisories

1
Debian
CVE-2026-24413: icinga2 - Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prio...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-24413 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-24413 — Incorrect Default Permissions | cvebase