CVE-2025-27406: Icinga ICINGAWEB2-Module-Reporting

High severity, CVSS 7.6. EPSS: 0.3% chance of exploitation in the next 30 days.

Icinga Reporting is the central component for reporting related functionality in the monitoring web frontend and framework Icinga Web 2. A vulnerability present in versions 0.10.0 through 1.0.2 allows to set up a template that allows to embed arbitrary Javascript. This enables the attacker to act on behalf of the user, if the template is being previewed; and act on behalf of the headless browser, if a report using the template is printed to PDF. This issue has been resolved in version 1.0.3 of Icinga Reporting. As a workaround, review all templates and remove suspicious settings.

Affected products

  • Icinga ICINGAWEB2-Module-Reporting: from 0.10.0, before 1.0.3 (fixed in 1.0.3)

Published 2025-03-26. Last modified 2026-06-17.