Local File Inclusion in Linuxfabrik Monitoring Plugins for Icinga and Nagios
CVE-2026-67433

5.8MEDIUM

Key Information:

Vendor
CVE Published:
29 July 2026

What is CVE-2026-67433?

The Linuxfabrik monitoring plugins, used for Icinga and Nagios, have a local file inclusion vulnerability introduced in version 6.0.0. This vulnerability arises from a flawed logfile check database migration process, which allows a local user to create a symlink. This symlink can be exploited during a root-run check as the application improperly follows it while attempting to make a database connection. This poses a significant risk as it can lead to unauthorized access to sensitive files and potential system compromise.

Affected Version(s)

monitoring-plugins 6.0.0

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.