PT-2025-51789 · Nagios Enterprises · Nagios Xi

Published

2025-12-16

·

Updated

2025-12-24

·

CVE-2025-34288

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 2026R1.1
Description The software contains a flaw that allows for local privilege escalation. This is due to an unsafe interaction between sudo permissions and application file permissions. A maintenance script accessible to users can be executed as root via sudo, and includes a file writable by a lower-privileged user. An attacker with access to the application account can modify this file to introduce malicious code, which is then executed with root privileges when the script is run. Successful exploitation results in arbitrary code execution as the root user.
Recommendations Update to version 2026R1.1 or later.

Fix

LPE

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-34288

Affected Products

Nagios Xi