Access Control Flaw in Nagios Network Analyzer by Nagios
CVE-2025-28059
7.5HIGH
What is CVE-2025-28059?
An access control flaw in Nagios Network Analyzer version 2024R1.0.3 permits former users to maintain access to system functionalities even after their accounts have been deleted. This vulnerability arises due to inadequate session termination and improper handling of expired API tokens, allowing unauthorized users to exploit leftovers of active sessions and gain access to sensitive operations. Administrators need to ensure that any user deletion triggers a complete invalidation of all associated sessions and API tokens.