PT-2025-35099 · Nagios Enterprises · Nagios Xi
Published
2025-08-28
·
Updated
2025-09-08
·
CVE-2024-13986
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nagios XI versions prior to 2024R1.3.2
Description
Nagios XI is susceptible to remote code execution due to chained flaws: an arbitrary file upload and a path traversal within the Core Config Snapshots interface. Insufficient validation of file paths and extensions during MIB upload and snapshot rename operations allows attackers to place attacker-controlled PHP files in a web-accessible directory. These files are then executed as the www-data user.
Recommendations
Update Nagios XI to version 2024R1.3.2 or later.
Exploit
Fix
RCE
Path traversal
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nagios Xi