Executive brief
Nagios XI is an enterprise monitoring platform used to track infrastructure health and performance. A timing-based password brute force vulnerability in the authentication function allows attackers to guess the admin password by analyzing slight differences in response times, potentially leading to complete compromise of the monitoring system and exposure of monitored infrastructure.
Technical details
The vulnerability exists in the is_insecure_login_authenticated function, which uses insecure timing comparison to validate credentials. This timing attack allows an attacker to bruteforce the admin password by measuring response time differences—correct password characters take slightly longer to compare than incorrect ones, leaking information character-by-character. The attack is network-reachable and requires no prior authentication. Patches are available in Nagios XI 5.9.3 and later.
Affected products
- Nagios XI before 5.9.3
Timeline
- 2026-09-14: disclosed