Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker able to connect to TCP port 5665 can replace the node certificate and trusted CA certificate, impersonate a trusted node, and take control of the node. This issue is fixed in versions 2.14.9, 2.15.4, and 2.16.2.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-862"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61550.json"
}{
"extracted_events": [
{
"introduced": "2.8"
},
{
"fixed": "2.14.9"
},
{
"introduced": "2.15.0"
},
{
"fixed": "2.15.4"
},
{
"introduced": "2.16.0"
},
{
"fixed": "2.16.2"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-61550.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"210664276016879271991729067461967263691",
"60084191526426145694823184325138172049",
"157057593243643149005984172489367373276",
"270408842380583503830298287509521390260"
],
"threshold": 0.9
},
"id": "CVE-2026-61550-1e1262bd",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/icinga/icinga2/commit/4b7fb3405f4616a24b2b55e20f603a56b7dd6ad0",
"target": {
"file": "lib/remote/jsonrpcconnection-pki.cpp"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"210664276016879271991729067461967263691",
"60084191526426145694823184325138172049",
"157057593243643149005984172489367373276",
"270408842380583503830298287509521390260"
],
"threshold": 0.9
},
"id": "CVE-2026-61550-7a19d303",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/icinga/icinga2/commit/d37b0cfd7d9595ae2f02fadb3d724c98d8620f81",
"target": {
"file": "lib/remote/jsonrpcconnection-pki.cpp"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"210664276016879271991729067461967263691",
"60084191526426145694823184325138172049",
"157057593243643149005984172489367373276",
"270408842380583503830298287509521390260"
],
"threshold": 0.9
},
"id": "CVE-2026-61550-808f5f66",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/icinga/icinga2/commit/6c2e0db3819f859910a4ae265461cb51b1d2039c",
"target": {
"file": "lib/remote/jsonrpcconnection-pki.cpp"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"210664276016879271991729067461967263691",
"60084191526426145694823184325138172049",
"157057593243643149005984172489367373276",
"270408842380583503830298287509521390260"
],
"threshold": 0.9
},
"id": "CVE-2026-61550-8d7cfc24",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/icinga/icinga2/commit/a6f7cc7a4ef8beed023b24416106822d6940c4c0",
"target": {
"file": "lib/remote/jsonrpcconnection-pki.cpp"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "201925701246339456878585280727725614320",
"length": 2449
},
"id": "CVE-2026-61550-ac411240",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/icinga/icinga2/commit/4b7fb3405f4616a24b2b55e20f603a56b7dd6ad0",
"target": {
"file": "lib/remote/jsonrpcconnection-pki.cpp",
"function": "UpdateCertificateHandler"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "201925701246339456878585280727725614320",
"length": 2449
},
"id": "CVE-2026-61550-d275aaf1",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/icinga/icinga2/commit/6c2e0db3819f859910a4ae265461cb51b1d2039c",
"target": {
"file": "lib/remote/jsonrpcconnection-pki.cpp",
"function": "UpdateCertificateHandler"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "201925701246339456878585280727725614320",
"length": 2449
},
"id": "CVE-2026-61550-d89055ef",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/icinga/icinga2/commit/d37b0cfd7d9595ae2f02fadb3d724c98d8620f81",
"target": {
"file": "lib/remote/jsonrpcconnection-pki.cpp",
"function": "UpdateCertificateHandler"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "201925701246339456878585280727725614320",
"length": 2449
},
"id": "CVE-2026-61550-def9bbe5",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/icinga/icinga2/commit/a6f7cc7a4ef8beed023b24416106822d6940c4c0",
"target": {
"file": "lib/remote/jsonrpcconnection-pki.cpp",
"function": "UpdateCertificateHandler"
}
}
]
"2026-09-26T08:12:57Z"