Impact
Nagios Core and Nagios XI contain a CSRF flaw in the cmd.cgi module. When a request lacks a Cookie header, the double‑submit cookie mechanism can be bypassed by supplying matching NagFormId and nagFormId values in the POST data. This allows a cross‑site request to execute Nagios commands on the authenticated user’s behalf, potentially modifying monitoring settings, deleting services, or extracting sensitive log data. The impact is the compromise of command integrity and the ability to alter or disrupt monitoring configuration.
Affected Systems
Vendors affected are Nagios Enterprises, LLC with Nagios Core versions prior to 4.5.13 and Nagios XI versions prior to 2026R1.5. Updates to the mentioned version thresholds resolve the vulnerability.
Risk and Exploitability
The CVSS score of 6.9 rates this as a moderate severity flaw. No EPSS score is reported, and it is not listed in the CISA KEV catalog, which suggests that it may not yet have active exploits in the wild. The attack can be carried out from a malicious third‑party site by sending a crafted POST request containing the required form fields; successful exploitation requires that the victim be logged into Nagios as a role with command execution rights.
OpenCVE Enrichment