CVE-2026-67436

CVE-2026-67436CVE-2026-67436

Description

Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier, the redfish-* plugins built request URLs by concatenating an operator-supplied base URL with response-supplied @odata.id links, allowing a malicious or compromised BMC to redirect authenticated Redfish requests and disclose X-Auth-Token or HTTP Basic credentials.

Scoring

Last modified2026-07-29
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.