CVE-2025-27406
CVSS 3.1 Score 7.6 of 10 (high)
Details
Summary
CVE-2025-27406 is a vulnerability affecting Icinga Reporting, a component of Icinga Web 2's monitoring web frontend and framework. Versions 0.10.0 through 1.0.2 are impacted, allowing attackers to embed arbitrary Javascript into templates. This vulnerability enables the attacker to impersonate the user during template previews, or take control of headless browser actions when generating PDF reports. The issue has been fixed in Icinga Reporting version 1.0.3, and as a temporary measure, users are advised to review and remove any suspicious settings from their templates.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.