CVE-2026-2041
moderateAuthenticated Command Injection RCE in Nagios XI Zabbix Agent Config Wizard
CVE-2026-2041 is a command injection flaw (CWE-78) in the zabbixagent_configwizard_func method of Nagios XI (listed in the advisory under the vendor name 'Nagios Host'), allowing remote authenticated attackers to execute arbitrary code. It is triggered when a user-supplied string passed to the Zabbix Agent configuration wizard function is not properly validated before being used in a system call. An attacker with valid credentials can run code in the context of the service account, giving them control of the monitoring server at that account's privileges. Any organization running an affected Nagios XI installation is exposed, though exploitation requires a low-privilege authenticated account and access to the configuration wizard. No public PoC or confirmed in-the-wild exploitation is known yet, but the very high EPSS score (73.4% within 30 days, 99th percentile) suggests exploitation attempts are likely soon.
What to do: Update Nagios XI to the patched release identified in the vendor advisory once available, and in the meantime restrict which accounts can reach the configuration wizards. Place exposed Nagios XI servers behind a VPN or IP allowlist, enforce MFA on the web UI, and audit logs for unexpected system command activity originating from config wizard requests. Given the high EPSS score, prioritize patching and monitor for exploitation activity.
| nagios xi | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this vulnerability. The specific flaw exists within the zabbixagent_configwizard_func method. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-28250.
- Vendors
- nagios
- Products
- nagios xi
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.