Cross-Site Request Forgery Vulnerability in Nagios Core by Nagios
CVE-2026-48548

6.9MEDIUM

What is CVE-2026-48548?

Nagios Core prior to version 4.5.12 has a vulnerability that allows attackers to exploit the cmd.cgi script through Cross-Site Request Forgery (CSRF). When the NagFormId cookie is absent, the CSRF protection mechanism fails, allowing an attacker to craft a malicious unsolicited POST request. This could lead to the execution of arbitrary Nagios commands under the context of a currently authenticated user, without their explicit knowledge or consent, compromising the security and integrity of the user's Nagios environment.

Affected Version(s)

Nagios Core 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SeungMyung Lee
.