PatchSiren

Nagios Enterprises, LLC. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Nagios Enterprises, LLC. CVE published 2026-08-12

CVE-2026-48554

CVE-2026-48554 is a high-severity vulnerability in Nagios Core and XI that allows authenticated remote code execution via unfiltered NOTIFICATION-family macro substitution. Defenders should prioritize verification of configurations, especially those with non-default notification commands, and assess exposure to potential lateral movement and impact on monitoring systems. The vulnerability exists in Nagios [truncated]

HIGH Nagios Enterprises, LLC. CVE published 2026-08-12

CVE-2026-48553

CVE-2026-48553 debrief based on the supplied source corpus. The CVE record was published on 2026-08-12T17:17:27.697Z and has not been modified since then. This authenticated remote code execution vulnerability in Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 allows attackers with NRDP access to inject OS commands through custom-variable macro injection. Defenders should verify and remediate this [truncated]

MEDIUM Nagios Enterprises, LLC. CVE published 2026-08-12

CVE-2026-48552

CVE-2026-48552 is a DOM-based cross-site scripting vulnerability in Nagios Core before 4.5.14 and Nagios XI before 2026R1.7. The vulnerability exists in jsonquery.js, where unencoded JSON string values reflected from stored fields are inserted into the DOM without sanitization, allowing attackers to run arbitrary JavaScript in the victim's browser.

MEDIUM Nagios Enterprises, LLC. CVE published 2026-08-12

CVE-2026-48551

CVE-2026-48551 debrief: Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie, allowing unauthenticated attackers to run commands as authorized users via malicious links. This vulnerability enables attackers to bypass CSRF protection, potentially leading to lateral movement within the network. Defenders shoul [truncated]

MEDIUM Nagios Enterprises, LLC. CVE published 2026-08-12

CVE-2026-48550

CVE-2026-48550 debrief based on the supplied source corpus. The CVE record was published on 2026-08-12T17:17:27.190Z and has not been modified since then. This reflected cross-site scripting vulnerability in Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 requires verification of exposure, especially in environments with authenticated users who may follow malicious links. Defenders should assess p [truncated]