Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to an invalid value and, due to insufficient validation and authorization checks tied to email identity state, trigger inconsistent account state that granted elevated privileges or bypassed intended access controls.
                
            Metrics
Affected Vendors & Products
Advisories
    No advisories yet.
Fixes
    Solution
Nagios addresses this vulnerability as "Fixed a privilege escalation issue where a user can edit their own email and put in an invalid address."
Workaround
No workaround given by the vendor.
References
        History
                    Thu, 30 Oct 2025 21:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to an invalid value and, due to insufficient validation and authorization checks tied to email identity state, trigger inconsistent account state that granted elevated privileges or bypassed intended access controls. | |
| Title | Nagios Log Server < 2024R1.3.2 Set Email Privilege Escalation | |
| Weaknesses | CWE-281 | |
| References |  | |
| Metrics | cvssV4_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-10-30T21:25:52.056Z
Reserved: 2025-04-15T19:15:22.582Z
Link: CVE-2025-34298
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Received
Published: 2025-10-30T22:15:49.257
Modified: 2025-10-30T22:15:49.257
Link: CVE-2025-34298
 Redhat
                        Redhat
                    No data.
 OpenCVE Enrichment
                        OpenCVE Enrichment
                    No data.