Privilege Escalation in Linuxfabrik Monitoring Plugins for Icinga and Nagios
CVE-2026-52817
What is CVE-2026-52817?
Linuxfabrik Monitoring Plugins, used for monitoring systems like Icinga and Nagios, contains a critical flaw that permits the monitoring accounts to execute commands as root through unrestricted APT arguments. Specifically, prior to version 5.1.0, the policy file 'Debian.sudoers' allowed the execution of /usr/bin/apt-get without proper restrictions. This loophole enables an attacker, who has already gained control of a monitoring account, to exploit the APT::Update::Pre-Invoke option to run arbitrary commands, leading to a complete compromise of the host system. This vulnerability impacts the check-plugins/deb-updates/deb-updates plugin by allowing unauthorized command sequences. The issue was rectified in version 5.1.0.
Affected Version(s)
monitoring-plugins < 5.1.0
