Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-61909


Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, the safe-reload script (also used during systemctl reload icinga2) and logrotate configuration shipped with Icinga 2 read the PID of the main Icinga 2 process from a PID file writable by the daemon user, but send the signal as the root user. This can allow the Icinga user to send signals to processes it would otherwise not permitted to. A fix is included in the following Icinga 2 versions: 2.15.1, 2.14.7, and 2.13.13.


Published

2025-10-16T18:15:38.427

Last Modified

2025-10-29T20:03:42.687

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.4 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-250

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application icinga icinga < 2.13.13 Yes
Application icinga icinga < 2.14.7 Yes
Application icinga icinga 2.15.0 Yes

References