CVE-2026-61550
Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker able to connect to TCP port 5665 can replace the node certificate and trusted CA certificate, impersonate a trusted node, and take control of the node. This issue is fixed in versions 2.14.9, 2.15.4, and 2.16.2.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/Icinga/icinga2/releases/tag/v2.14.9, https://github.com/Icinga/icinga2/releases/tag/v2.15.4, https://github.com/Icinga/icinga2/releases/tag/v2.16.2, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61550.json, https://github.com/Icinga/icinga2/security/advisories/GHSA-vj39-ww8j-vvx5, https://nvd.nist.gov/vuln/detail/CVE-2026-61550, https://github.com/Icinga/icinga2/commit/4b7fb3405f4616a24b2b55e20f603a56b7dd6ad0, https://github.com/Icinga/icinga2/commit/6c2e0db3819f859910a4ae265461cb51b1d2039c, https://github.com/Icinga/icinga2/commit/a6f7cc7a4ef8beed023b24416106822d6940c4c0, https://github.com/Icinga/icinga2/commit/d37b0cfd7d9595ae2f02fadb3d724c98d8620f81, https://github.com/Icinga/icinga2/pull/10907, https://icinga.com/blog/icinga2-security-release-v2-16-2