MEDIUM 6.9 NVD
CVE-2026-48549
Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSRF vulnerability in cmd.cgi. When no Cookie header is present, the double-submit cookie pro
Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSRF vulnerability in cmd.cgi. When no Cookie header is present, the double-submit cookie protection can be bypassed by supplying matching NagFormId and nagFormId values in the POST body, allowing a cross-site request to execute Nagios commands as a currently authenticated user.
References
- https://github.com/NagiosEnterprises/nagioscore/blob/master/Changelog
- https://www.nagios.com/security-disclosures/nagios-core/
- https://www.vulncheck.com/advisories/nagios-core-xi-csrf-via-cmd-cgi-double-submit-cookie
This medium severity vulnerability with a CVSS score of 6.9 was published on 2026-08-26 via NVD.
vulnfeed aggregates 11364 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.