Incorrect Authorization Vulnerability in Nagios Log Server
CVE-2023-7322

8.7HIGH

Key Information:

Vendor

NagiOS

Vendor
CVE Published:
30 October 2025

What is CVE-2023-7322?

An incorrect authorization vulnerability exists in Nagios Log Server which affects versions prior to 2024R1. This flaw allows users without the necessary API permissions to access API endpoints, resulting in unintended access to sensitive data and actions. As a consequence, authenticated users can potentially read or modify resources they are not authorized to interact with, highlighting a serious security oversight that requires immediate attention.

Affected Version(s)

Log Server 0 < 2024R1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-7322 : Incorrect Authorization Vulnerability in Nagios Log Server