<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Nagios - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/nagios/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 12 Aug 2026 18:50:49 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/nagios/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Nagios Core and XI CSRF Protection Bypass</title><link>https://feed.craftedsignal.io/briefs/2026-08-nagios-csrf-bypass/</link><pubDate>Wed, 12 Aug 2026 18:50:49 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-nagios-csrf-bypass/</guid><description>Nagios Core and XI contain a CSRF protection bypass vulnerability (CVE-2026-48551) that allows unauthenticated attackers to execute commands as an authorized user via manipulated double-submit cookies.</description><content:encoded><![CDATA[<p>Nagios Core (versions prior to 4.5.14) and Nagios XI (versions prior to 2026R1.7) are susceptible to a cross-site request forgery (CSRF) protection bypass identified as CVE-2026-48551. The vulnerability stems from an insecure implementation of double-submit cookie validation. By supplying matching cookie and request parameter values, an attacker can circumvent the application's CSRF defenses. This allows an unauthenticated remote attacker to trick an authenticated user into unknowingly executing malicious actions or commands within the web interface, essentially hijacking the user's session context for unauthorized tasks. This issue is significant for security and infrastructure monitoring platforms, as successful exploitation could lead to full system control or configuration changes by unauthorized parties.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a high risk to organizations relying on Nagios for infrastructure monitoring, as it permits unauthenticated remote attackers to perform actions with the privileges of an active, authenticated administrator session. Potential damage includes unauthorized modification of monitoring configurations, deletion of critical alerts, or the execution of arbitrary system commands through the application's administrative interface.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for administrators and security teams:</p>
<ul>
<li>Upgrade Nagios Core to version 4.5.14 or later immediately.</li>
<li>Upgrade Nagios XI to version 2026R1.7 or later immediately.</li>
<li>Restrict network access to Nagios administrative interfaces using IP whitelisting or VPNs to limit the exposure of the vulnerable web endpoints until patches are applied.</li>
<li>Audit web server access logs for requests containing suspicious or inconsistent cookie-to-parameter values that suggest an attempt to bypass standard CSRF protections.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>rce</category><category>monitoring</category></item></channel></rss>