Description
Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection through the Nagios Remote Data Processor (NRDP). When a custom variable defined on a host, service, or contact is referenced in a shell-executed command line, an authenticated attacker with NRDP access can inject OS commands through the macro value. Exploitation requires a non-default configuration in which a custom variable is defined and referenced in a shell-executed command.
Published: 2026-08-12
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A custom-variable macro injection flaw allows an attacker who has authenticated access to the Nagios Remote Data Processor (NRDP) to execute arbitrary operating‑system commands on the host where Nagios is running. When a custom variable defined on a host, service, or contact is inserted into a shell‑executed command line, the attacker can embed malicious commands within the macro value. This results in full compromise of the monitored system’s confidentiality, integrity, and availability.

Affected Systems

Nagios Core versions earlier than 4.5.13 and Nagios XI versions earlier than 2026R1.5 are affected. The vulnerability is present in products supplied by Nagios Enterprises, LLC.

Risk and Exploitability

The CVSS score of 7.7 indicates a high severity risk. An exploitation attempt requires the attacker to have NRDP credentials and a system that has enabled a non-default custom variable referenced in a remote command. While the EPSS score is not available and the vulnerability is not in the CISA KEV catalog, the combination of authenticated access and the ability to execute arbitrary commands makes this a critical threat for environments that use NRDP and expose custom variables to shell commands.

Generated by OpenCVE AI on August 12, 2026 at 23:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch: upgrade to Nagios Core 4.5.13 or later or Nagios XI 2026R1.5 or later.
  • If a patch is not immediately available, remove or disable NRDP access for the affected users, or restrict the NRDP account’s privileges so that it cannot execute commands or modify custom variables.
  • Modify configuration to eliminate any custom variables that are interpolated into shell command lines, ensuring that all command executions use safe, hard‑coded arguments.

Generated by OpenCVE AI on August 12, 2026 at 23:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:nagios:nagios_core:*:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Nagios
Nagios nagios Core
Nagios nagios Xi
Vendors & Products Nagios
Nagios nagios Core
Nagios nagios Xi

Wed, 12 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection through the Nagios Remote Data Processor (NRDP). When a custom variable defined on a host, service, or contact is referenced in a shell-executed command line, an authenticated attacker with NRDP access can inject OS commands through the macro value. Exploitation requires a non-default configuration in which a custom variable is defined and referenced in a shell-executed command.
Title Nagios Core / XI Authenticated RCE via Custom-Variable Macro Injection
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Nagios Nagios Core Nagios Xi
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-14T16:50:00.508Z

Reserved: 2026-05-21T18:34:46.418Z

Link: CVE-2026-48553

cve-icon Vulnrichment

Updated: 2026-08-12T17:55:18.775Z

cve-icon NVD

Status : Received

Published: 2026-08-12T17:17:27.697

Modified: 2026-08-12T20:17:44.590

Link: CVE-2026-48553

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:48:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')