CVE-2026-48551: Nagios Core / XI CSRF Protection Bypass via Double-Submit Cookie
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply matching cookie and request parameter values to bypass CSRF protection, enabling unauthenticated attackers to run commands as authorized users via malicious links.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nagios Coreto a version that resolves this vulnerability.Fixed in 4.5.14 - Upgrade
Upgrade
Nagios XIto a version that resolves this vulnerability.Fixed in 2026R1.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48551?
CVE-2026-48551 has a severity rating of high with a score of 7.4.
How do I fix CVE-2026-48551?
To mitigate CVE-2026-48551, upgrade Nagios Core to version 4.5.14 or later and Nagios XI to version 2026R1.7 or later.
What type of vulnerability is CVE-2026-48551?
CVE-2026-48551 is a cross-site request forgery (CSRF) protection bypass vulnerability.
Who is affected by CVE-2026-48551?
Users running Nagios Core prior to version 4.5.14 and Nagios XI prior to version 2026R1.7 are affected by CVE-2026-48551.
What is the impact of CVE-2026-48551?
CVE-2026-48551 enables unauthenticated attackers to perform actions on behalf of legitimate users by bypassing CSRF protection.