CVE-2026-48550: Nagios Core / XI cmd.cgi Reflected XSS via NagFormId Parameter
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An unauthenticated remote attacker can craft a malicious link that, when followed by an authenticated user, executes arbitrary JavaScript in the victim's browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48550?
CVE-2026-48550 has a medium severity score of 6.1.
How do I fix CVE-2026-48550?
To fix CVE-2026-48550, upgrade Nagios Core to version 4.5.14 or later and Nagios XI to version 2026R1.7 or later.
What type of vulnerability is CVE-2026-48550?
CVE-2026-48550 is a reflected cross-site scripting (XSS) vulnerability.
Who can exploit CVE-2026-48550?
An unauthenticated remote attacker can exploit CVE-2026-48550 by crafting a malicious link that targets an authenticated user.
What components are affected by CVE-2026-48550?
CVE-2026-48550 affects Nagios Core versions before 4.5.14 and Nagios XI versions prior to 2026R1.7.