← Back to browse · API

CVE-2026-2043

Severity
HIGH
CVSS
7.2
EPSS
0.72908
Risk score
54.32
CISA KEV
No
PoC
No
Published
2026-02-20
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2026-7770, GHSA-Q77W-WGHG-55FV
Products
Nagios:Host 2026R1
Sources
euvd EUVD-2026-7770

Description

Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this vulnerability. The specific flaw exists within the esensors_websensor_configwizard_func method. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-28249.

References