Security Flaw in Icinga PowerShell Framework Exposes Private Keys
CVE-2026-24414

6.8MEDIUM

Key Information:

Vendor

Icinga

Vendor
CVE Published:
29 January 2026

What is CVE-2026-24414?

The Icinga PowerShell Framework, used for monitoring Windows environments, has a significant vulnerability in versions before 1.13.4, 1.12.4, and 1.11.2. The 'certificate' directory's permissions allow any user to read sensitive data, notably the private key of the Icinga certificate for the host. This exposure can lead to unauthorized access and compromise system security. Users must update to the fixed versions to resolve this issue and are advised to restrict access manually by updating the ACL for the relevant directories. This incident has implications beyond Icinga for Windows, as it also affects Icinga 2 with related vulnerabilities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

icinga-powershell-framework < 1.11.2 < 1.11.2

icinga-powershell-framework >= 1.12.0, < 1.12.4 < 1.12.0, 1.12.4

icinga-powershell-framework >= 1.13.0, < 1.13.4 < 1.13.0, 1.13.4

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.