Authentication Bypass in Icinga 2 Monitoring System
CVE-2025-61907

7.1HIGH

Key Information:

Vendor

Icinga

Status
Vendor
CVE Published:
16 October 2025

What is CVE-2025-61907?

In Icinga 2, an open-source monitoring solution, a vulnerability affects versions 2.4 through 2.15.0 where improperly handled filter expressions on the /v1/objects endpoints expose sensitive global variables and objects. This flaw permits authenticated API users to access restricted information not intended for their permission level, resulting in potential information disclosure. The issue is rectified in versions 2.15.1, 2.14.7, and 2.13.13. For further details on the vulnerability, you can refer to the security advisory and the commit details.

Affected Version(s)

icinga2 >= 2.15.0, < 2.15.1 < 2.15.0, 2.15.1

icinga2 >= 2.14.0, < 2.14.7 < 2.14.0, 2.14.7

icinga2 >= 2.4.0, < 2.13.13 < 2.4.0, 2.13.13

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-61907 : Authentication Bypass in Icinga 2 Monitoring System