Nagios Log Server Incorrect Authorization Vulnerability Allowing Unprivileged API Access

Vulnerability

A vulnerability exists in Nagios Log Server versions prior to 2024R1, where incorrect authorization allows users without the necessary API permissions to access API endpoints. This flaw enables authenticated but non-privileged users to read or modify resources beyond their authorized rights, leading to unintended access to data and actions available through the API.

Impact

Exploitation of this vulnerability could result in unauthorized access to data and actions via the API, allowing users to read or modify resources beyond their intended rights.

Remediation

Users can upgrade to Nagios Log Server version 2024R1 or later to address this vulnerability.

Added: Oct 30, 2025, 11:02 PM
Updated: Oct 30, 2025, 11:02 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
5.0
exploitability
5.2
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.