CSRF Protection Bypass in Nagios Core and Nagios XI
CVE-2026-48551
6.1MEDIUM
Key Information:
- Vendor
NagiOS Enterprises, Llc.
- Status
- Vendor
- CVE Published:
- 12 August 2026
What is CVE-2026-48551?
Nagios Core and Nagios XI are vulnerable to a CSRF protection bypass due to an issue involving a double-submit cookie mechanism. An attacker can exploit this vulnerability by crafting malicious links that leverage a self-supplied cookie and corresponding request parameters. This allows unauthenticated attackers to execute commands on behalf of legitimate users, posing a significant risk to the integrity and security of systems using these products.
Affected Version(s)
Nagios Core 0
Nagios XI 0
