Nagios Log Server Local Privilege Escalation Vulnerability

Vulnerability

A local privilege escalation vulnerability has been identified in Nagios Log Server versions prior to 2024R1.0.2. This vulnerability allows an attacker with the ability to execute commands as the Apache web user or the backend shell user to escalate privileges to root on the host.

Impact

Exploitation of this vulnerability allows for unauthorized privilege escalation from the Apache or backend shell user to the root user on the host system.

Remediation

Users are advised to upgrade to Nagios Log Server version 2024R1.0.2 or above.

Added: Oct 30, 2025, 10:37 PM
Updated: Oct 30, 2025, 10:37 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
5.0
exploitability
3.8
remediation
7.7
relevance
0.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.