← Back to browse · API

CVE-2026-2041

Severity
HIGH
CVSS
7.2
EPSS
0.73366
Risk score
54.48
CISA KEV
No
PoC
No
Published
2026-02-20
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2026-7769, GHSA-QP8F-9474-HR27
Products
Nagios:Host 2026R1
Sources
euvd EUVD-2026-7769

Description

Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this vulnerability. The specific flaw exists within the zabbixagent_configwizard_func method. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-28250.

References