Authenticated Remote Code Execution Vulnerability in Nagios Core and XI
CVE-2026-48553

7.7HIGH

What is CVE-2026-48553?

Nagios Core versions prior to 4.5.13 and Nagios XI versions before 2026R1.5 are susceptible to an authenticated remote code execution vulnerability. This issue arises from improper handling of custom variable macro injections via the Nagios Remote Data Processor (NRDP). When an authenticated user with NRDP access defines a custom variable and incorporates it into a shell-executed command line, they could inject and execute arbitrary OS commands. Exploitation is contingent upon a non-standard configuration that references a custom variable in a vulnerable manner, posing a significant security risk.

Affected Version(s)

Nagios Core 0

Nagios XI 0

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.