logo

Nagios XI OS Command Injection Vulnerability

ID: 0a827bbb-10e3-50ed-98e4-94a48055eb60

STIX ID: report--0a827bbb-10e3-50ed-98e4-94a48055eb60

Feed Name: NCC Research

Threat Score
70/100

Date Published: 2026-05-14

Date Updated: 2026-08-01

...
...

Nagios XI Network Monitor 2011R1.9 contains an authenticated OS command injection in the Graph Explorer component (visApi.php) via GET parameters (host, service, opt, end, start); a proof-of-concept demonstrates it can read /etc/passwd. The flaw was reported by Daniel Compton and resolved in Graph Explorer SVN 1.3 (05/23/2012).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.