ZeroHour

CVE-2026-2041

moderate

Authenticated Command Injection RCE in Nagios XI Zabbix Agent Config Wizard

CVSS 3.1
8.8 high
EPSS
73%p99
Published
()
Modified
AI analysis

CVE-2026-2041 is a command injection flaw (CWE-78) in the zabbixagent_configwizard_func method of Nagios XI (listed in the advisory under the vendor name 'Nagios Host'), allowing remote authenticated attackers to execute arbitrary code. It is triggered when a user-supplied string passed to the Zabbix Agent configuration wizard function is not properly validated before being used in a system call. An attacker with valid credentials can run code in the context of the service account, giving them control of the monitoring server at that account's privileges. Any organization running an affected Nagios XI installation is exposed, though exploitation requires a low-privilege authenticated account and access to the configuration wizard. No public PoC or confirmed in-the-wild exploitation is known yet, but the very high EPSS score (73.4% within 30 days, 99th percentile) suggests exploitation attempts are likely soon.

What to do: Update Nagios XI to the patched release identified in the vendor advisory once available, and in the meantime restrict which accounts can reach the configuration wizards. Place exposed Nagios XI servers behind a VPN or IP allowlist, enforce MFA on the web UI, and audit logs for unexpected system command activity originating from config wizard requests. Given the high EPSS score, prioritize patching and monitor for exploitation activity.

Affected
nagios xi
Estimated exposure
moderateLow thousands of internet-exposed Nagios XI servers (public scans); total deployments likely in the tens of thousands, mostly on internal networks — Public internet scans index only a few thousand Nagios XI web interfaces, and Nagios XI is typically deployed as an internal monitoring appliance behind firewalls, so the directly exposed population is much smaller than the total install…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this vulnerability. The specific flaw exists within the zabbixagent_configwizard_func method. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-28250.

Vendors
nagios
Products
nagios xi
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.