CSRF Vulnerability in Nagios Core and Nagios XI Products by Nagios
CVE-2026-48549
6.9MEDIUM
Key Information:
- Vendor
NagiOS Enterprises, Llc.
- Status
- Vendor
- CVE Published:
- 26 August 2026
What is CVE-2026-48549?
A Cross-Site Request Forgery (CSRF) vulnerability exists in Nagios Core versions prior to 4.5.13 and Nagios XI versions prior to 2026R1.5. This flaw allows an attacker to exploit a weakness in the cmd.cgi component. Specifically, without a Cookie header present, the built-in double-submit cookie protection mechanism can be circumvented by sending matching values for NagFormId in the POST body. As a result, an attacker can execute Nagios commands as if they were an authenticated user, potentially compromising system integrity.
Affected Version(s)
Nagios Core 0
Nagios XI 0
