CVE-2025-27406

CVSS 3.1 Score 7.6 of 10 (high)

Details

Published Mar 26, 2025
Updated: Mar 27, 2025
CWE ID 918
CWE ID 79

Summary

CVE-2025-27406 is a vulnerability affecting Icinga Reporting, a component of Icinga Web 2's monitoring web frontend and framework. Versions 0.10.0 through 1.0.2 are impacted, allowing attackers to embed arbitrary Javascript into templates. This vulnerability enables the attacker to impersonate the user during template previews, or take control of headless browser actions when generating PDF reports. The issue has been fixed in Icinga Reporting version 1.0.3, and as a temporary measure, users are advised to review and remove any suspicious settings from their templates.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share