Privilege Escalation Vulnerability in Nagios XI by Nagios Enterprises
CVE-2020-36868

8.5HIGH

Key Information:

Vendor

NagiOS

Status
Vendor
CVE Published:
30 October 2025

What is CVE-2020-36868?

Nagios XI versions before 5.7.3 contain a vulnerability in the getprofile.sh script that could allow a local attacker to escalate their privileges. Due to insecure handling of files and insufficient validation of user inputs, this vulnerability could be exploited to execute arbitrary commands or manipulate privileged files, especially as the script is often run with elevated privileges. Organizations using affected versions are urged to upgrade to mitigate potential security risks.

Affected Version(s)

XI 0 < 5.7.3

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Christian Weiler
.
CVE-2020-36868 : Privilege Escalation Vulnerability in Nagios XI by Nagios Enterprises