Authentication Bypass in Icinga 2 Monitoring System
CVE-2025-61907
What is CVE-2025-61907?
In Icinga 2, an open-source monitoring solution, a vulnerability affects versions 2.4 through 2.15.0 where improperly handled filter expressions on the /v1/objects endpoints expose sensitive global variables and objects. This flaw permits authenticated API users to access restricted information not intended for their permission level, resulting in potential information disclosure. The issue is rectified in versions 2.15.1, 2.14.7, and 2.13.13. For further details on the vulnerability, you can refer to the security advisory and the commit details.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
icinga2 >= 2.15.0, < 2.15.1 < 2.15.0, 2.15.1
icinga2 >= 2.14.0, < 2.14.7 < 2.14.0, 2.14.7
icinga2 >= 2.4.0, < 2.13.13 < 2.4.0, 2.13.13
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
