← Vulnerability feed

Vulnerability record · CVE-2025-30164 · published 26 March 2025

CVE-2025-30164: Icinga web 2 open redirect vulnerability

Icinga · Icinga Web 2

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 vulnerability allows an attacker to craft a URL that, once visited by an authenticated user (or one that is able to authenticate), allows to manipulate the backend to redirect the user to any location. This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2. No known workarounds are available.

6.1 CVSS 3.1 Medium EPSS 0.26% · top 83.6% CWE-601 · Open redirect
6.1CVSS 3.1 base score
0.26%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 vulnerability allows an attacker to craft a URL that, once visited by an authenticated user (or one that is able to authenticate), allows to manipulate the backend to redirect the user to any location. This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2. No known workarounds are available.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-30164 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-18249Icinga web 2 code injection vulnerabilityIcinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send information …EPSS 1.5%8.8CVE-2022-24715Icinga web 2 path traversal vulnerabilityIcinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration,…EPSS 15%7.5CVE-2022-24716Icinga Web 2 unauthenticated path traversal file disclosureIcinga Web 2 fails to properly restrict path traversal, letting unauthenticated users read files on the local system that are accessible to the web-s…EPSS 89%analysed7.5CVE-2020-24368Icinga web 2 path traversal vulnerabilityIcinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files th…EPSS 3.3%7.5CVE-2018-18250Icinga web 2 injection vulnerabilityIcinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navigation ite…EPSS 1.00%6.5CVE-2018-18246Icinga web 2 cross-site request forgery vulnerabilityIcinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via /icingaweb2/config/m…EPSS 0.46%6.1CVE-2025-27405Icinga web 2 cross-site scripting vulnerabilityIcinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.1…EPSS 0.33%6.1CVE-2025-27404Icinga web 2 cross-site scripting vulnerabilityIcinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.1…EPSS 0.60%

Source: NIST National Vulnerability Database (record CVE-2025-30164), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.