CVE-2025-34227: Nagios XI < 2026R1 Configuration Wizard Authenticated Command Injection
Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It is possible to inject shell characters into arguments provided to the service and execute arbitrary system commands on the underlying host as the nagios user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34227?
CVE-2025-34227 is categorized as a high severity vulnerability due to its potential for exploiting authenticated command injection.
How do I fix CVE-2025-34227?
To mitigate CVE-2025-34227, upgrade Nagios XI to version 2026R1 or later.
Who is affected by CVE-2025-34227?
CVE-2025-34227 affects users of Nagios XI versions prior to 2026R1.
What types of services are vulnerable in CVE-2025-34227?
CVE-2025-34227 impacts the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards.
Can CVE-2025-34227 lead to data breaches?
Yes, CVE-2025-34227 can potentially allow attackers to execute arbitrary commands, leading to data breaches.