Skip to content
Threat Feed
high advisory

Nagios Core and XI CSRF Protection Bypass

Nagios Core and XI contain a CSRF protection bypass vulnerability (CVE-2026-48551) that allows unauthenticated attackers to execute commands as an authorized user via manipulated double-submit cookies.

CVE search metadata

CVE search record: CVE-2026-48551. Severity: high. CVSS: 7.4. KEV: no. Product: Nagios Core, Nagios XI. Brief: Nagios Core and XI CSRF Protection Bypass. Brief link: https://feed.craftedsignal.io/briefs/2026-08-nagios-csrf-bypass/

What's new

  • 1. added coverage for Nagios Core +1 products Aug 12, 18:50 via nvd

Nagios Core (versions prior to 4.5.14) and Nagios XI (versions prior to 2026R1.7) are susceptible to a cross-site request forgery (CSRF) protection bypass identified as CVE-2026-48551. The vulnerability stems from an insecure implementation of double-submit cookie validation. By supplying matching cookie and request parameter values, an attacker can circumvent the application's CSRF defenses. This allows an unauthenticated remote attacker to trick an authenticated user into unknowingly executing malicious actions or commands within the web interface, essentially hijacking the user's session context for unauthorized tasks. This issue is significant for security and infrastructure monitoring platforms, as successful exploitation could lead to full system control or configuration changes by unauthorized parties.

Impact

The vulnerability poses a high risk to organizations relying on Nagios for infrastructure monitoring, as it permits unauthenticated remote attackers to perform actions with the privileges of an active, authenticated administrator session. Potential damage includes unauthorized modification of monitoring configurations, deletion of critical alerts, or the execution of arbitrary system commands through the application's administrative interface.

Recommendation

Prioritized actions for administrators and security teams:

  • Upgrade Nagios Core to version 4.5.14 or later immediately.
  • Upgrade Nagios XI to version 2026R1.7 or later immediately.
  • Restrict network access to Nagios administrative interfaces using IP whitelisting or VPNs to limit the exposure of the vulnerable web endpoints until patches are applied.
  • Audit web server access logs for requests containing suspicious or inconsistent cookie-to-parameter values that suggest an attempt to bypass standard CSRF protections.

Immediate actions

Patch Nagios Core and Nagios XI to specified versions

IT Operations 48h