Nagios XI Privilege Escalation Vulnerability in System Profile Component

Vulnerability

A privilege escalation vulnerability has been identified in Nagios XI versions prior to 2024R1.0.1. This vulnerability resides in the System Profile component, which is used for administrative diagnostics and configuration. The issue arises from inadequate access controls and improper handling of exported and imported profile data. An authenticated administrator could exploit this vulnerability to perform actions on the underlying XI host that bypass the application's security measures. Successful exploitation could grant the administrator root privileges on the XI server.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an administrator to gain root access on the server where Nagios XI is installed.

Remediation

Users can upgrade to Nagios XI version 2024R1.0.1 or later to address this vulnerability.

Added: Oct 30, 2025, 10:40 PM
Updated: Oct 30, 2025, 10:40 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
10.0
exploitability
4.8
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.