PT-2025-35099 · Nagios Enterprises · Nagios Xi

CVE-2024-13986

·

Published

2025-08-28

·

Updated

2025-09-08

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 2024R1.3.2
Description Nagios XI is susceptible to remote code execution due to chained flaws: an arbitrary file upload and a path traversal within the Core Config Snapshots interface. Insufficient validation of file paths and extensions during MIB upload and snapshot rename operations allows attackers to place attacker-controlled PHP files in a web-accessible directory. These files are then executed as the www-data user.
Recommendations Update Nagios XI to version 2024R1.3.2 or later.

Exploit

Fix

RCE

Path traversal

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-13986

Affected Products

Nagios Xi