Impact
A custom-variable macro injection flaw allows an attacker who has authenticated access to the Nagios Remote Data Processor (NRDP) to execute arbitrary operating‑system commands on the host where Nagios is running. When a custom variable defined on a host, service, or contact is inserted into a shell‑executed command line, the attacker can embed malicious commands within the macro value. This results in full compromise of the monitored system’s confidentiality, integrity, and availability.
Affected Systems
Nagios Core versions earlier than 4.5.13 and Nagios XI versions earlier than 2026R1.5 are affected. The vulnerability is present in products supplied by Nagios Enterprises, LLC.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity risk. An exploitation attempt requires the attacker to have NRDP credentials and a system that has enabled a non-default custom variable referenced in a remote command. While the EPSS score is not available and the vulnerability is not in the CISA KEV catalog, the combination of authenticated access and the ability to execute arbitrary commands makes this a critical threat for environments that use NRDP and expose custom variables to shell commands.
OpenCVE Enrichment