Impact
This vulnerability allows a cross‑site request forgery protection bypass in Nagios Core and Nagios XI. By supplying a self‑supplied double‑submit cookie that matches a request parameter, an attacker can defeat the CSRF checks and trigger privileged commands to be executed on the server. The weakness is a classic CSRF bypass (CWE‑352).
Affected Systems
Nagios Enterprises, LLC's Nagios Core versions earlier than 4.5.14 and Nagios XI versions earlier than 2026R1.7 are vulnerable.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate risk, and no EPSS score is available, so exploitation likelihood is unknown. The vulnerability is not listed in the CISA KEV catalog. According to the description, unauthenticated attackers can supply a matching cookie and request parameter to bypass CSRF defenses, allowing them to execute privileged commands as if they were an authenticated user.
OpenCVE Enrichment