← Vulnerability feed

Vulnerability record · CVE-2018-18249 · published 17 December 2018

CVE-2018-18249: Icinga web 2 code injection vulnerability

Icinga · Icinga Web 2

Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send information to the attacker, such as a name=${PATH}_${APACHE_RUN_DIR}_${APACHE_RUN_USER} parameter to /icingaweb2/navigation/add or /icingaweb2/dashboard/new-dashlet.

9.8 CVSS 3.0 Critical EPSS 1.5% · top 27.0% CWE-94 · Code injection
9.8CVSS 3.0 base score, v2 7.5
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send information to the attacker, such as a name=${PATH}_${APACHE_RUN_DIR}_${APACHE_RUN_USER} parameter to /icingaweb2/navigation/add or /icingaweb2/dashboard/new-dashlet.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-18249 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-24715Icinga web 2 path traversal vulnerabilityIcinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration,…EPSS 15%7.5CVE-2022-24716Icinga Web 2 unauthenticated path traversal file disclosureIcinga Web 2 fails to properly restrict path traversal, letting unauthenticated users read files on the local system that are accessible to the web-s…EPSS 89%analysed7.5CVE-2020-24368Icinga web 2 path traversal vulnerabilityIcinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files th…EPSS 3.3%7.5CVE-2018-18250Icinga web 2 injection vulnerabilityIcinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navigation ite…EPSS 1.00%6.5CVE-2018-18246Icinga web 2 cross-site request forgery vulnerabilityIcinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via /icingaweb2/config/m…EPSS 0.46%6.1CVE-2025-30164Icinga web 2 open redirect vulnerabilityIcinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.1…EPSS 0.26%6.1CVE-2025-27405Icinga web 2 cross-site scripting vulnerabilityIcinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.1…EPSS 0.33%6.1CVE-2025-27404Icinga web 2 cross-site scripting vulnerabilityIcinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.1…EPSS 0.60%

Source: NIST National Vulnerability Database (record CVE-2018-18249), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.