PT-2026-71150 · Nagios Enterprises+3 · Nagios Core+2

·

CVE-2026-48551

·

Published

2026-08-12

·

Updated

2026-08-12

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Nagios Core versions prior to 4.5.14 Nagios XI versions prior to 2026R1.7
Description Cross-site request forgery (CSRF) protection bypass occurs when an attacker provides a self-supplied double-submit cookie. By supplying matching cookie and request parameter values, unauthenticated attackers can bypass security protections and execute commands as authorized users through malicious links. Double-submit cookies are a stateless CSRF defense mechanism where a random value is sent both in a cookie and a request parameter; the server validates that both values match.
Recommendations Update Nagios Core to version 4.5.14 or later. Update Nagios XI to version 2026R1.7 or later.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48551

Affected Products

Nagios Core
Nagios Xi
Nagios4