Privilege Escalation in Linuxfabrik Monitoring Plugins for Icinga and Nagios
CVE-2026-52817

7HIGH

Key Information:

Vendor
CVE Published:
18 August 2026

What is CVE-2026-52817?

Linuxfabrik Monitoring Plugins, used for monitoring systems like Icinga and Nagios, contains a critical flaw that permits the monitoring accounts to execute commands as root through unrestricted APT arguments. Specifically, prior to version 5.1.0, the policy file 'Debian.sudoers' allowed the execution of /usr/bin/apt-get without proper restrictions. This loophole enables an attacker, who has already gained control of a monitoring account, to exploit the APT::Update::Pre-Invoke option to run arbitrary commands, leading to a complete compromise of the host system. This vulnerability impacts the check-plugins/deb-updates/deb-updates plugin by allowing unauthorized command sequences. The issue was rectified in version 5.1.0.

Affected Version(s)

monitoring-plugins < 5.1.0

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.