{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/nagios/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-48551"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Nagios Core","Nagios XI"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","monitoring"],"_cs_type":"advisory","_cs_vendors":["Nagios"],"content_html":"\u003cp\u003eNagios Core (versions prior to 4.5.14) and Nagios XI (versions prior to 2026R1.7) are susceptible to a cross-site request forgery (CSRF) protection bypass identified as CVE-2026-48551. The vulnerability stems from an insecure implementation of double-submit cookie validation. By supplying matching cookie and request parameter values, an attacker can circumvent the application's CSRF defenses. This allows an unauthenticated remote attacker to trick an authenticated user into unknowingly executing malicious actions or commands within the web interface, essentially hijacking the user's session context for unauthorized tasks. This issue is significant for security and infrastructure monitoring platforms, as successful exploitation could lead to full system control or configuration changes by unauthorized parties.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a high risk to organizations relying on Nagios for infrastructure monitoring, as it permits unauthenticated remote attackers to perform actions with the privileges of an active, authenticated administrator session. Potential damage includes unauthorized modification of monitoring configurations, deletion of critical alerts, or the execution of arbitrary system commands through the application's administrative interface.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for administrators and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Nagios Core to version 4.5.14 or later immediately.\u003c/li\u003e\n\u003cli\u003eUpgrade Nagios XI to version 2026R1.7 or later immediately.\u003c/li\u003e\n\u003cli\u003eRestrict network access to Nagios administrative interfaces using IP whitelisting or VPNs to limit the exposure of the vulnerable web endpoints until patches are applied.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for requests containing suspicious or inconsistent cookie-to-parameter values that suggest an attempt to bypass standard CSRF protections.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-12T18:50:57Z","date_published":"2026-08-12T18:50:49Z","id":"https://feed.craftedsignal.io/briefs/2026-08-nagios-csrf-bypass/","summary":"Nagios Core and XI contain a CSRF protection bypass vulnerability (CVE-2026-48551) that allows unauthenticated attackers to execute commands as an authorized user via manipulated double-submit cookies.","title":"Nagios Core and XI CSRF Protection Bypass","url":"https://feed.craftedsignal.io/briefs/2026-08-nagios-csrf-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Nagios","version":"https://jsonfeed.org/version/1.1"}