CVE-2025-34227
PoC largeAuthenticated Command Injection in Nagios XI Database Wizards
CVE-2025-34227 is an authenticated OS command injection flaw (CWE-78) in Nagios XI versions prior to 2026R1, affecting the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query configuration wizards. An authenticated user with access to these wizards can inject shell metacharacters into arguments passed to the underlying database services, causing arbitrary system commands to execute on the host. Successful exploitation yields remote code execution on the monitoring server as the nagios user, potentially enabling pivoting, tampering with monitoring data, or broader network access. All Nagios XI deployments before 2026R1 are affected, and the CVSS 4.0 vector indicates exploitation requires high-level privileges with no user interaction. A public proof-of-concept write-up exists, but there is no confirmed in-the-wild exploitation or KEV listing yet; however, an EPSS of 24.3% (98th percentile) signals elevated exploitation risk over the next 30 days.
What to do: Upgrade to Nagios XI 2026R1 or later to remediate. Until patched, restrict access to the database wizards to trusted, highly privileged accounts, enforce strong authentication on the XI web interface, and review logs for unexpected processes or commands run as the nagios user. Given the elevated EPSS (24.3%), prioritize patching internet-exposed instances first.
| nagios xi | < 2026R1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It is possible to inject shell characters into arguments provided to the service and execute arbitrary system commands on the underlying host as the `nagios` user.
- Vendors
- nagios
- Products
- nagios xi
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.