CVE-2026-24413 | Icinga icinga2 up to 2.13.13/2.14.7/2.15.1 on Windows Service default permission (GHSA-88h5-rrm6-5973 / EUVD-2026-4959)
A vulnerability marked as critical has been reported in Icinga icinga2 up to 2.13.13/2.14.7/2.15.1 on Windows. The affected element is an unknown function of the component Service. This manipulation causes incorrect default permissions.
The identification of this vulnerability is CVE-2026-24413. The attack can only be executed locally. There is no exploit available.
It is suggested to upgrade the affected component.