Get real-time updates on Telegram
CVE-2025-61907: icinga 2.15.0; +1 more affected products
CVE-2025-61907. CVSS 3.1 base score 6.5 (MEDIUM, NVD). EPSS 0.00404 (percentile 0.32511), scored 2026-10-08.
Affected technology
icinga · from 2.4.0 (inclusive), before 2.13.13 (exclusive)
icinga
icinga · from 2.14.0 (inclusive), before 2.14.7 (exclusive)
icinga
icinga · 2.15.0
icinga
icinga2 · >= 2.15.0, < 2.15.1, >= 2.14.0, < 2.14.7, >= 2.4.0, < 2.13.13
Icinga
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required
What an attacker can do
Authenticated API users can learn information that should be hidden from them, including global variables not permitted by the variables permission and objects not permitted by the corresponding objects/query permissions. Vendor/CNA’s CVSS 4.0 assessment (base score 7.1/10) rates confidentiality impact as high; integrity and availability impact as none.
- CWE
- CWE-200, CWE-204, CWE-749
- CCR priority
- 26.1 /100 (P4)
- CVSS 3.1
- 6.5 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N · NVD
- EPSS
- 0.00404 · percentile 0.32511 · 2026-10-08
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-09 12:21:30.679837+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-61907.html