High severityNVD Advisory· Published Jul 29, 2026· Updated Jul 30, 2026
CVE-2026-67436
CVE-2026-67436
Description
Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier, the redfish-* plugins built request URLs by concatenating an operator-supplied base URL with response-supplied @odata.id links, allowing a malicious or compromised BMC to redirect authenticated Redfish requests and disclose X-Auth-Token or HTTP Basic credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=6.0.0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.