CVE-2026-48552: Nagios Core / XI DOM-based XSS via jsonquery.js
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js. Unencoded JSON string values reflected from stored fields are inserted into the DOM without sanitization, allowing attackers to run arbitrary JavaScript in the victim's browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48552?
CVE-2026-48552 has a medium severity rating of 5.4.
How do I fix CVE-2026-48552?
To fix CVE-2026-48552, update to Nagios Core version 4.5.14 or later and Nagios XI version 2026R1.7 or later.
What types of attacks can exploit CVE-2026-48552?
CVE-2026-48552 can be exploited through DOM-based cross-site scripting attacks that run arbitrary JavaScript in a victim's browser.
Which software versions are affected by CVE-2026-48552?
CVE-2026-48552 affects Nagios Core versions prior to 4.5.14 and Nagios XI versions prior to 2026R1.7.
What is the nature of the vulnerability in CVE-2026-48552?
CVE-2026-48552 is a DOM-based XSS vulnerability due to unencoded JSON string values being inserted into the DOM without sanitization.