CVE-2026-67436: Linuxfabrik Monitoring-Plugins
High severity, CVSS 8.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier, the redfish-* plugins built request URLs by concatenating an operator-supplied base URL with response-supplied @odata.id links, allowing a malicious or compromised BMC to redirect authenticated Redfish requests and disclose X-Auth-Token or HTTP Basic credentials.
Affected products
- Linuxfabrik Monitoring-Plugins: up to and including 6.0.0
Published 2026-07-29. Last modified 2026-07-30.