CVE-2025-34286: Nagios XI < 2026R1 RCE via Run Check Command in CCM
Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run Check command. Insufficient validation/escaping of parameters used to build backend command lines allows an authenticated administrator to inject shell metacharacters that are executed on the server. Successful exploitation results in arbitrary command execution with the privileges of the Nagios XI web application user and can be leveraged to gain control of the underlying host operating system.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34286?
CVE-2025-34286 has been classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-34286?
To fix CVE-2025-34286, upgrade Nagios XI to version 2026R1 or later.
Who is affected by CVE-2025-34286?
CVE-2025-34286 affects authenticated administrators of Nagios XI versions prior to 2026R1.
What kind of vulnerability is CVE-2025-34286?
CVE-2025-34286 is a remote code execution vulnerability found in the Core Config Manager of Nagios XI.
Can CVE-2025-34286 be exploited remotely?
Yes, CVE-2025-34286 can potentially be exploited remotely by authenticated users with sufficient privileges.