Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability via the experimental 'Natural Language Queries' feature. Configuration values for this feature are read from the application settings and incorporated into a system command without adequate validation or restriction of special characters. An authenticated user with access to global configuration can abuse these settings to execute arbitrary operating system commands with the privileges of the web server account, leading to compromise of the Log Server host.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 17 Nov 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nagios
Nagios log Server |
|
| CPEs | cpe:2.3:a:nagios:log_server:2026:*:*:*:*:*:*:* | |
| Vendors & Products |
Nagios
Nagios log Server |
Mon, 17 Nov 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability via the experimental 'Natural Language Queries' feature. Configuration values for this feature are read from the application settings and incorporated into a system command without adequate validation or restriction of special characters. An authenticated user with access to global configuration can abuse these settings to execute arbitrary operating system commands with the privileges of the web server account, leading to compromise of the Log Server host. | |
| Title | Nagios Log Server < 2026R1.0.1 Authenticated Command Injection via Natural Language Queries | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-11-17T21:36:26.201Z
Reserved: 2025-04-15T19:15:22.585Z
Link: CVE-2025-34322
No data.
Status : Received
Published: 2025-11-17T18:15:56.710
Modified: 2025-11-17T18:15:56.710
Link: CVE-2025-34322
No data.
OpenCVE Enrichment
No data.