{"id":"CVE-2026-61552","summary":"Icinga 2 DSL Injection via Unescaped Import Template Name","details":"Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes attacker-controlled template names into generated configuration without escaping them. An authenticated ApiUser with an objects/create/* permission can inject Icinga 2 DSL configuration, escape the intended object, create additional objects, and exceed the user's assigned privileges. This issue is fixed in versions 2.14.9, 2.15.4, and 2.16.2.","aliases":["GHSA-jgqj-x5j9-vgcm"],"modified":"2026-09-20T14:24:10.063036Z","published":"2026-09-18T17:24:42.394Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-94"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61552.json"},"references":[{"type":"WEB","url":"https://github.com/Icinga/icinga2/releases/tag/v2.14.9"},{"type":"WEB","url":"https://github.com/Icinga/icinga2/releases/tag/v2.15.4"},{"type":"WEB","url":"https://github.com/Icinga/icinga2/releases/tag/v2.16.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61552.json"},{"type":"ADVISORY","url":"https://github.com/Icinga/icinga2/security/advisories/GHSA-jgqj-x5j9-vgcm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61552"},{"type":"FIX","url":"https://github.com/Icinga/icinga2/commit/125b7734e84d03f09b79d36c270152b11629a8c5"},{"type":"FIX","url":"https://github.com/Icinga/icinga2/commit/af4b36e6464b9b214bed270a53d6474cf91eb441"},{"type":"FIX","url":"https://github.com/Icinga/icinga2/commit/eec0d90e8303376fe772b3e4a04e3b064a44cf30"},{"type":"FIX","url":"https://github.com/Icinga/icinga2/commit/faf0450962ad678397991cfdf041810feafa71e7"},{"type":"FIX","url":"https://github.com/Icinga/icinga2/pull/10910"},{"type":"ARTICLE","url":"https://icinga.com/blog/icinga2-security-release-v2-16-2"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/icinga/icinga2","events":[{"introduced":"ac7f4fada837587568d069341e6dc11c309afb78"},{"introduced":"f87948081fc2386fc7a30eb12ab01cb907dbe3fb"},{"introduced":"5855790474c50904efd0c9e31968c04938960a01"},{"fixed":"75b2d7a1c9eacb58e3e3025a6e5f4f573f922d23"},{"fixed":"b4ec974518c9e5f5ca861169442ac3780e675767"},{"fixed":"cfdf63b6331c73fecb2de433022e950cf5184d02"},{"fixed":"125b7734e84d03f09b79d36c270152b11629a8c5"},{"fixed":"af4b36e6464b9b214bed270a53d6474cf91eb441"},{"fixed":"eec0d90e8303376fe772b3e4a04e3b064a44cf30"},{"fixed":"faf0450962ad678397991cfdf041810feafa71e7"}],"database_specific":{"extracted_events":[{"introduced":"2.4"},{"fixed":"2.14.9"},{"introduced":"2.15.0"},{"fixed":"2.15.4"},{"introduced":"2.16.0"},{"fixed":"2.16.2"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v2.16.1","v2.16.0","v2.15.3","v2.14.5","v2.15.0","v2.14.4","v2.14.2","v2.14.1","v2.14.0","v2.13.0","v2.12.0","v2.11.0","v2.12.0-rc1","v2.11.0-rc1","v2.10.1","v2.10.0","v2.9.0","v2.7.0","v2.6.1","v2.6.0","v2.5.0","v2.4.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-61552.json","vanir_signatures_modified":"2026-09-20T14:24:10Z","vanir_signatures":[{"digest":{"line_hashes":["59899725601018182516792911217307821527","129977937418125232374674937563614655038","71065345085471113227799827662163349187","279318950991862264849474981758633920510"],"threshold":0.9},"id":"CVE-2026-61552-21c75934","signature_type":"Line","signature_version":"v1","source":"https://github.com/icinga/icinga2/commit/af4b36e6464b9b214bed270a53d6474cf91eb441","target":{"file":"lib/base/configwriter.hpp"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"267381947322668360558648684449444235221","length":881},"id":"CVE-2026-61552-37e6bce0","signature_type":"Function","signature_version":"v1","source":"https://github.com/icinga/icinga2/commit/eec0d90e8303376fe772b3e4a04e3b064a44cf30","target":{"file":"lib/base/configwriter.cpp","function":"ConfigWriter::EmitScope"}},{"digest":{"line_hashes":["106757867239695335712174213460390906041","97749299920142283549346335891331204672","204780741062044310861033395915111145796","215389316788068430871667946617824162396","327048152677635572200887907722822677582","183045592543193529424289644348787035288","21182394755458444494645020712612968363","85674943352650593287789976331583757241","332048325784111845672029237039027725677","320573121894957912360087867808230076635","271465232327094196450288203775352056841"],"threshold":0.9},"id":"CVE-2026-61552-40dd5ed4","signature_type":"Line","signature_version":"v1","source":"https://github.com/icinga/icinga2/commit/eec0d90e8303376fe772b3e4a04e3b064a44cf30","target":{"file":"lib/base/configwriter.cpp"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"60945322493185959739419995176459144129","length":114},"id":"CVE-2026-61552-66601bee","signature_type":"Function","signature_version":"v1","source":"https://github.com/icinga/icinga2/commit/125b7734e84d03f09b79d36c270152b11629a8c5","target":{"file":"lib/base/configwriter.cpp","function":"ConfigWriter::EmitComment"}},{"id":"CVE-2026-61552-6c8eca72","signature_type":"Line","signature_version":"v1","source":"https://github.com/icinga/icinga2/commit/faf0450962ad678397991cfdf041810feafa71e7","target":{"file":"lib/base/configwriter.cpp"},"deprecated":false,"digest":{"line_hashes":["106757867239695335712174213460390906041","97749299920142283549346335891331204672","204780741062044310861033395915111145796","215389316788068430871667946617824162396","327048152677635572200887907722822677582","183045592543193529424289644348787035288","21182394755458444494645020712612968363","85674943352650593287789976331583757241","332048325784111845672029237039027725677","320573121894957912360087867808230076635","271465232327094196450288203775352056841"],"threshold":0.9}},{"digest":{"function_hash":"60945322493185959739419995176459144129","length":114},"id":"CVE-2026-61552-7de531a6","signature_type":"Function","signature_version":"v1","source":"https://github.com/icinga/icinga2/commit/af4b36e6464b9b214bed270a53d6474cf91eb441","target":{"file":"lib/base/configwriter.cpp","function":"ConfigWriter::EmitComment"},"deprecated":false},{"deprecated":false,"digest":{"length":114,"function_hash":"60945322493185959739419995176459144129"},"id":"CVE-2026-61552-97acb725","signature_type":"Function","signature_version":"v1","source":"https://github.com/icinga/icinga2/commit/faf0450962ad678397991cfdf041810feafa71e7","target":{"file":"lib/base/configwriter.cpp","function":"ConfigWriter::EmitComment"}},{"source":"https://github.com/icinga/icinga2/commit/125b7734e84d03f09b79d36c270152b11629a8c5","target":{"file":"lib/base/configwriter.cpp","function":"ConfigWriter::EmitScope"},"deprecated":false,"digest":{"function_hash":"267381947322668360558648684449444235221","length":881},"id":"CVE-2026-61552-9bda42a2","signature_type":"Function","signature_version":"v1"},{"digest":{"line_hashes":["59899725601018182516792911217307821527","129977937418125232374674937563614655038","71065345085471113227799827662163349187","279318950991862264849474981758633920510"],"threshold":0.9},"id":"CVE-2026-61552-a0962ac6","signature_type":"Line","signature_version":"v1","source":"https://github.com/icinga/icinga2/commit/eec0d90e8303376fe772b3e4a04e3b064a44cf30","target":{"file":"lib/base/configwriter.hpp"},"deprecated":false},{"digest":{"function_hash":"267381947322668360558648684449444235221","length":881},"id":"CVE-2026-61552-a6e2eeb5","signature_type":"Function","signature_version":"v1","source":"https://github.com/icinga/icinga2/commit/af4b36e6464b9b214bed270a53d6474cf91eb441","target":{"function":"ConfigWriter::EmitScope","file":"lib/base/configwriter.cpp"},"deprecated":false},{"source":"https://github.com/icinga/icinga2/commit/eec0d90e8303376fe772b3e4a04e3b064a44cf30","target":{"file":"lib/base/configwriter.cpp","function":"ConfigWriter::EmitComment"},"deprecated":false,"digest":{"function_hash":"60945322493185959739419995176459144129","length":114},"id":"CVE-2026-61552-b9086f39","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"line_hashes":["59899725601018182516792911217307821527","129977937418125232374674937563614655038","71065345085471113227799827662163349187","279318950991862264849474981758633920510"],"threshold":0.9},"id":"CVE-2026-61552-ba999714","signature_type":"Line","signature_version":"v1","source":"https://github.com/icinga/icinga2/commit/125b7734e84d03f09b79d36c270152b11629a8c5","target":{"file":"lib/base/configwriter.hpp"}},{"source":"https://github.com/icinga/icinga2/commit/af4b36e6464b9b214bed270a53d6474cf91eb441","target":{"file":"lib/base/configwriter.cpp"},"deprecated":false,"digest":{"line_hashes":["106757867239695335712174213460390906041","97749299920142283549346335891331204672","204780741062044310861033395915111145796","215389316788068430871667946617824162396","327048152677635572200887907722822677582","183045592543193529424289644348787035288","21182394755458444494645020712612968363","85674943352650593287789976331583757241","332048325784111845672029237039027725677","320573121894957912360087867808230076635","271465232327094196450288203775352056841"],"threshold":0.9},"id":"CVE-2026-61552-c352d75d","signature_type":"Line","signature_version":"v1"},{"target":{"file":"lib/base/configwriter.cpp"},"deprecated":false,"digest":{"line_hashes":["106757867239695335712174213460390906041","97749299920142283549346335891331204672","204780741062044310861033395915111145796","215389316788068430871667946617824162396","327048152677635572200887907722822677582","183045592543193529424289644348787035288","21182394755458444494645020712612968363","85674943352650593287789976331583757241","332048325784111845672029237039027725677","320573121894957912360087867808230076635","271465232327094196450288203775352056841"],"threshold":0.9},"id":"CVE-2026-61552-c5a76988","signature_type":"Line","signature_version":"v1","source":"https://github.com/icinga/icinga2/commit/125b7734e84d03f09b79d36c270152b11629a8c5"},{"signature_version":"v1","source":"https://github.com/icinga/icinga2/commit/faf0450962ad678397991cfdf041810feafa71e7","target":{"file":"lib/base/configwriter.hpp"},"deprecated":false,"digest":{"line_hashes":["59899725601018182516792911217307821527","129977937418125232374674937563614655038","71065345085471113227799827662163349187","279318950991862264849474981758633920510"],"threshold":0.9},"id":"CVE-2026-61552-c82d4b2d","signature_type":"Line"},{"id":"CVE-2026-61552-f3e74bd1","signature_type":"Function","signature_version":"v1","source":"https://github.com/icinga/icinga2/commit/faf0450962ad678397991cfdf041810feafa71e7","target":{"file":"lib/base/configwriter.cpp","function":"ConfigWriter::EmitScope"},"deprecated":false,"digest":{"function_hash":"267381947322668360558648684449444235221","length":881}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}