PT-2025-44521 · Nagios Enterprises · Nagios Xi

Published

2025-10-30

·

Updated

2025-10-31

·

CVE-2025-34283

CVSS v2.0
9.0
VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 2024R1.4.2
Description Nagios XI versions prior to 2024R1.4.2 had a flaw where API keys were exposed to users lacking the necessary API access permissions when utilizing Neptune themes. An authenticated user, even without API privileges, could view the API key value belonging to another user or their own. The affected API keys were revealed through the use of Neptune themes.
Recommendations Update to version 2024R1.4.2 or later.

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-14701
CVE-2025-34283

Affected Products

Nagios Xi