Executive brief
Nagios Core and Nagios XI are monitoring systems used to track the health and performance of IT infrastructure. An authenticated attacker with access to the Nagios Remote Data Processor (NRDP) can inject operating system commands by manipulating custom variable values, potentially gaining full control of the monitoring server. This requires non-default configuration where custom variables are referenced in shell commands, but in affected deployments could enable complete system compromise.
Technical details
The vulnerability is an OS command injection flaw in Nagios Core (before 4.5.13) and Nagios XI (before 2026R1.5) that occurs when custom variables defined on hosts, services, or contacts are referenced in shell-executed command lines. An authenticated attacker with NRDP access can inject arbitrary OS commands through the custom variable macro value. The attack requires authentication and a non-default configuration where custom variables are actually referenced in shell commands. Successful exploitation allows remote code execution with the privileges of the Nagios process, potentially compromising the entire monitoring infrastructure. Patches are available in Nagios Core 4.5.13 and Nagios XI 2026R1.5.
Affected products
- Nagios Enterprises Nagios Core before 4.5.13
- Nagios Enterprises Nagios XI before 2026R1.5
Timeline
- 2026-08-12: disclosed: CVE-2026-48553 published