Authorization Flaw in Nagios Log Server Enables Dashboard Deletions by Non-Admins
CVE-2025-34273
What is CVE-2025-34273?
Nagios Log Server versions before 2024R2.0.3 are susceptible to an incorrect authorization vulnerability. This issue permits non-administrator users to delete global dashboards without the necessary permissions, compromising the integrity of shared monitoring environments. As the application fails to enforce adequate authorization checks during the dashboard deletion process, affected users can inadvertently remove critical dashboards that are vital for other team members, potentially impacting overall system monitoring and operations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Log Server 0 < 2024R2.0.3
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
