ZeroHour

CVE-2025-34227

PoC large

Authenticated Command Injection in Nagios XI Database Wizards

CVSS 4.0
8.6 high
EPSS
24%p98
Published
()
Modified
AI analysis

CVE-2025-34227 is an authenticated OS command injection flaw (CWE-78) in Nagios XI versions prior to 2026R1, affecting the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query configuration wizards. An authenticated user with access to these wizards can inject shell metacharacters into arguments passed to the underlying database services, causing arbitrary system commands to execute on the host. Successful exploitation yields remote code execution on the monitoring server as the nagios user, potentially enabling pivoting, tampering with monitoring data, or broader network access. All Nagios XI deployments before 2026R1 are affected, and the CVSS 4.0 vector indicates exploitation requires high-level privileges with no user interaction. A public proof-of-concept write-up exists, but there is no confirmed in-the-wild exploitation or KEV listing yet; however, an EPSS of 24.3% (98th percentile) signals elevated exploitation risk over the next 30 days.

What to do: Upgrade to Nagios XI 2026R1 or later to remediate. Until patched, restrict access to the database wizards to trusted, highly privileged accounts, enforce strong authentication on the XI web interface, and review logs for unexpected processes or commands run as the nagios user. Given the elevated EPSS (24.3%), prioritize patching internet-exposed instances first.

Affected
nagios xi< 2026R1
Estimated exposure
large≈tens of thousands of deployments (public internet scans show thousands of exposed Nagios XI instances, with many more internal-only) — Nagios XI is a widely deployed on-premises monitoring platform used by enterprises and MSPs, and public internet-wide scans typically enumerate thousands to tens of thousands of exposed instances, so total deployments plausibly fall in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It is possible to inject shell characters into arguments provided to the service and execute arbitrary system commands on the underlying host as the `nagios` user.

Vendors
nagios
Products
nagios xi
Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.