ZeroHour

CVE-2026-2043

moderate

Authenticated Command Injection RCE in Nagios XI

CVSS 3.1
8.8 high
EPSS
73%p99
Published
()
Modified
AI analysis

Nagios XI contains an authenticated command injection flaw (CWE-78) in the esensors_websensor_configwizard_func method, disclosed through Trend Micro's Zero Day Initiative (ZDI-CAN-28249). The method fails to validate a user-supplied string before passing it to a system call, so a remote attacker with valid low-privilege credentials can inject operating system commands, for example via the E-sensors/WEBSensor configuration wizard component. Successful exploitation yields arbitrary code execution in the context of the service account on the Nagios host. Any organization running Nagios XI is potentially affected, though the authentication requirement limits the practical attack surface relative to unauthenticated flaws. No in-the-wild exploitation or public proof-of-concept is known and the flaw is not in CISA KEV, but its very high EPSS score (72.9% probability of exploitation within 30 days, 99th percentile) signals an elevated near-term exploitation risk.

What to do: Apply the Nagios XI security update addressing CVE-2026-2043 (ZDI-CAN-28249) as soon as it is available, since exact fixed versions are not specified in this data; verify against the Nagios/ZDI advisory. Until patched, restrict access to the Nagios XI web interface to trusted networks, minimize and monitor low-privilege accounts that can reach the configuration wizard, and watch the service account for unexpected process or command activity. Check whether the E-sensors/WEBSensor wizard component is in use and review logs for anomalous requests to its endpoints.

Affected
Nagios XI
Estimated exposure
moderateOn the order of a few thousand internet-exposed Nagios XI instances, with total deployments likely in the tens of thousands — Public internet scans typically index only a few thousand Nagios XI web front-ends, while the product's enterprise install base suggests tens of thousands of deployments, most running behind authentication inside corporate networks; Nagios…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this vulnerability. The specific flaw exists within the esensors_websensor_configwizard_func method. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-28249.

Vendors
nagios
Products
nagios xi
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.