CVE 8.6 HIGH

Nagios XI < 2026R1 Configuration Wizard Authenticated Command Injection_CVE-2025-34227

8.6 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It is possible to inject shell characters into arguments provided to the service and execute arbitrary system commands on the underlying host as the `nagios` user.

Basic Information

ID CVE-2025-34227
Source VulnCheck
Published Sep 25, 2025 at 17:08

Affected Product

Vendor Nagios
Product Nagios XI
Version *
Affected Versions Nagios Nagios XI *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.