Impact
A vulnerability in Nagios Core and Nagios XI allows authenticated UI users to execute arbitrary shell commands by exploiting unfiltered substitution of $NOTIFICATIONCOMMENT$ or $NOTIFICATIONAUTHOR$ in notification commands. The flaw operates when a notification command references these macros in a shell‑reachable position, enabling privileged execution as the nagios user and thus compromising confidentiality, integrity, and availability. The weakness is an example of CWE‑78: Improper Neutralization of Special Elements used in a Command Injection context.
Affected Systems
The issue affects Nagios Core versions prior to 4.5.14 and Nagios XI versions prior to 2026R1.7. Any installation using these versions with a non‑default configuration that places the mentioned macros in a shell‑executed command line is susceptible.
Risk and Exploitability
The CVSS score for this vulnerability is 7.7, indicating a high severity. The EPSS score is not available and it is not listed in the CISA KEV catalog, implying no currently known widespread exploitation. Successful exploitation requires an authenticated UI user and a configuration that includes the problematic macros in a shell‑executed command line. Because the attack vector is internal and requires credentialed access, the probability of exploitation may be lower, yet the impact remains severe.
OpenCVE Enrichment