Redfish Plugin Vulnerability in Linuxfabrik Monitoring Plugins
CVE-2026-67436
8.3HIGH
What is CVE-2026-67436?
The Linuxfabrik monitoring-plugins, specifically the redfish-* plugins, are susceptible to URL construction vulnerabilities. These plugins, used for monitoring systems like Icinga and Nagios, concatenate an operator-defined base URL with response-supplied @odata.id links. This flaw allows a malicious or compromised baseboard management controller (BMC) to craft requests that improperly redirect authenticated Redfish calls, potentially revealing sensitive credentials such as X-Auth-Token or HTTP Basic authentication credentials.
Affected Version(s)
monitoring-plugins <= 6.0.0
