← Back to browse · API

CVE-2025-34227

Severity
HIGH
CVSS
8.6
EPSS
0.24251
Risk score
42.89
CISA KEV
No
PoC
No
Published
2025-09-25
Modified
2026-05-15
First seen
2026-08-07
Aliases
EUVD-2025-31147, GHSA-3GHQ-RFPW-JHQX
Products
Nagios Enterprises:Nagios XI 0 <2026R1
Sources
euvd EUVD-2025-31147

Description

Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It is possible to inject shell characters into arguments provided to the service and execute arbitrary system commands on the underlying host as the `nagios` user.

References