PT-2025-51789 · Nagios Enterprises · Nagios Xi
Published
2025-12-16
·
Updated
2025-12-24
·
CVE-2025-34288
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Nagios XI versions prior to 2026R1.1
Description
The software contains a flaw that allows for local privilege escalation. This is due to an unsafe interaction between sudo permissions and application file permissions. A maintenance script accessible to users can be executed as root via sudo, and includes a file writable by a lower-privileged user. An attacker with access to the application account can modify this file to introduce malicious code, which is then executed with root privileges when the script is run. Successful exploitation results in arbitrary code execution as the root user.
Recommendations
Update to version 2026R1.1 or later.
Fix
LPE
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nagios Xi