Open Source Monitoring System Icinga 2 Vulnerability in JSON Parsing
CVE-2026-61551

8.6HIGH

Key Information:

Vendor

Icinga

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-61551?

Icinga 2, an open source monitoring solution, has been found to have a vulnerability in its JSON parsing mechanism. The issue lies in the lack of bounds on the depth of nested JSON processing. This flaw can be exploited by unauthenticated clients connected to the service on TCP port 5665, potentially leading to a crash of the Icinga 2 process. Although there has been no demonstration of code execution via this vulnerability, it highlights a significant risk in system stability. The vulnerability has been addressed in versions 2.14.9, 2.15.4, and 2.16.2, offering users improvements for enhanced protection.

Affected Version(s)

icinga2 < 2.14.9 < 2.14.9

icinga2 >= 2.15.0, < 2.15.4 < 2.15.0, 2.15.4

icinga2 >= 2.16.0, < 2.16.2 < 2.16.0, 2.16.2

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.