CVE-2026-48549: Nagios Core / XI CSRF via cmd.cgi Double-Submit Cookie

Published Aug 26, 2026
·
Updated

Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSRF vulnerability in cmd.cgi. When no Cookie header is present, the double-submit cookie protection can be bypassed by supplying matching NagFormId and nagFormId values in the POST body, allowing a cross-site request to execute Nagios commands as a currently authenticated user.

Affected Software

2 affected components
Nagios Nagios Core<4.5.13
Nagios XI<2026R1.5

Event History

Aug 26, 2026
CVE Published
via MITRE·03:37 PM
Data Sourced
via MITRE·03:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can be affected by this issue?

Nagios Core versions before 4.5.13 and Nagios XI versions before 2026R1.5 are affected when a user is currently authenticated to the Nagios web interface.

2

What does an attacker need to exploit it?

The attacker does not need Nagios credentials, but must cause an authenticated user to submit a cross-site POST request. The request must omit the Cookie header and include matching NagFormId and nagFormId values in the POST body.

3

What is the impact of a successful attack?

A successful attack can execute Nagios commands with the permissions of the authenticated user. The stated impact is integrity loss, with no stated confidentiality or availability impact.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203