Local Privilege Escalation Vulnerability in Nagios XI by Nagios
CVE-2025-34288
8.6HIGH
What is CVE-2025-34288?
Nagios XI, specifically versions prior to 2026R1.1, exhibits a vulnerability that allows local privilege escalation. The issue arises from an insecure interaction between sudo permissions and the file permissions of application components. A maintenance script that can be accessed by users may be incorrectly executed with root privileges through sudo, exposing a writable application file. This allows a local attacker with access to modify the file to include malicious code. When the script is subsequently executed, it operates under elevated privileges, leading to the possibility of arbitrary code execution as the root user.
Affected Version(s)
Nagios XI 0 < 2026R1.1
