CVE-2026-48554: Nagios Core / XI Authenticated RCE via Unfiltered NOTIFICATION-Family Macro Substitution
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macro substitution through the comdata parameter. When a notification command references $NOTIFICATIONCOMMENT$ or $NOTIFICATIONAUTHOR$ in a shell-reachable position, authenticated UI users can run arbitrary commands as the nagios user. Exploitation requires a non-default configuration in which a notification command references these macros in a shell-executed command line.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nagios Coreto a version that resolves this vulnerability.Fixed in 4.5.14 - Upgrade
Upgrade
Nagios XIto a version that resolves this vulnerability.Fixed in 2026R1.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48554?
The severity of CVE-2026-48554 is high, rated at 7.5 on the CVSS scale.
How do I fix CVE-2026-48554?
To fix CVE-2026-48554, upgrade Nagios Core to version 4.5.14 or Nagios XI to version 2026R1.7 or later.
What type of vulnerability is CVE-2026-48554?
CVE-2026-48554 is an authenticated remote code execution vulnerability due to unfiltered macro substitution.
Which versions of Nagios are affected by CVE-2026-48554?
Nagios Core versions before 4.5.14 and Nagios XI versions before 2026R1.7 are affected by CVE-2026-48554.
Can CVE-2026-48554 lead to data compromise?
Yes, CVE-2026-48554 can compromise confidentiality, integrity, and availability due to the ability to execute arbitrary commands.