CVE-2025-61909: medium-severity vulnerability in icinga2
Icinga 2 signals sent as root to processes based on PID file written by the Icinga 2 daemon user
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4epss 0.2%
exploitation probability
0.2%top 89% of all CVEs
observed exploitation
nono source reports it
Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, the safe-reload script (also used during systemctl reload icinga2) and logrotate configuration shipped with Icinga 2 read the PID of the main Icinga 2 process from a PID file writable by the daemon user, but send the signal as the root user. This can allow the Icinga user to send signals to processes it would otherwise not permitted to. A fix is included in the following Icinga 2 versions: 2.15.1, 2.14.7, and 2.13.13.
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H
Affected products
Icinga · icinga2Related CVEs — icinga2
In the same product, most dangerous first.
CVE-2024-49369CRITICALIcinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API ConnectionsEPSS 2.9%CVE-2021-32743HIGHPasswords used to access external services inadvertently exposed through APIEPSS 1.8%CVE-2021-37698HIGHMissing TLS service certificate validation in GelfWriter, ElasticsearchWriter, InfluxdbWriter and Influxdb2WriterEPSS 1.4%CVE-2021-32739HIGHResults of queries for ApiListener objects include the ticket salt which allows in turn to steal (more privileged) identitiesEPSS 1.1%CVE-2026-61551HIGHIcinga 2: Stack overflow via deeply nested JSON objectsEPSS 0.9%CVE-2026-61552HIGHIcinga 2 DSL Injection via Unescaped Import Template NameEPSS 0.9%
References
https://github.com/Icinga/icinga2/commit/51ec73cbd922a76fc0f60e1d8d33acd7caa5d587https://github.com/Icinga/icinga2/issues/10527https://github.com/Icinga/icinga2/security/advisories/GHSA-pg6g-g99v-mw46https://icinga.com/blog/releasing-icinga-2-v2-15-1-2-14-7-and-2-13-13-and-icinga-db-web-v1-2-3-and-1-1-4