CVE-2025-61907

Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to the various /v1/objects endpoints could access variables or objects that would otherwise be inaccessible for the user. This allows authenticated API users to learn information that should be hidden from them, including global variables not permitted by the variables permission and objects not permitted by the corresponding objects/query permissions. The vulnerability is fixed in versions 2.15.1, 2.14.7, and 2.13.13.
CVSS

No CVSS.

Configurations

No configuration.

History

16 Oct 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-16 18:15

Updated : 2025-10-21 19:31


NVD link : CVE-2025-61907

Mitre link : CVE-2025-61907

CVE.ORG link : CVE-2025-61907


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-204

Observable Response Discrepancy

CWE-749

Exposed Dangerous Method or Function