Nagios XI
cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*
- < 2026R1
A command injection vulnerability has been identified in Nagios XI versions prior to 2026R1. This vulnerability resides within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It allows authenticated users to inject shell characters into arguments, which could then be used to execute arbitrary system commands on the host machine as the 'nagios' user.
Exploitation of this vulnerability allows for authenticated command injection, leading to arbitrary command execution on the server where Nagios XI is installed.
To reproduce this vulnerability, an authenticated user can navigate to the 'Configuration Wizard' section and select either the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, or Postgres Query wizards. While configuring these wizards, inject shell metacharacters into the command arguments. Once the wizard is saved, the injected commands will be executed on the server as the 'nagios' user.
Users can upgrade to Nagios XI 2026R1 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.