CVE-2025-34227
Last modified
CVE-2025-34227 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It is possible to inject shell characters into arguments provided to the service and execute arbitrary system commands on the underlying host as the `nagios` user.. EPSS estimates a 25.92% chance of exploitation in the next 30 days.
Description
Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It is possible to inject shell characters into arguments provided to the service and execute arbitrary system commands on the underlying host as the `nagios` user.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nagios | Nagios Xi | <= 2026 |
References
- https://theyhack.me/CVE-2025-34227-Nagios-XI-Wizard-Command-Injection/Exploit, Third Party Advisory
- https://www.nagios.com/changelog/Release Notes
- https://www.nagios.com/products/security/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-34227?
How severe is CVE-2025-34227?
How do I fix CVE-2025-34227?
Are you affected by CVE-2025-34227?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
