CVE-2025-34227

Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It is possible to inject shell characters into arguments provided to the service and execute arbitrary system commands on the underlying host as the `nagios` user.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*

History

14 Oct 2025, 19:53

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*
First Time Nagios
Nagios nagios Xi
References () https://theyhack.me/CVE-2025-34227-Nagios-XI-Wizard-Command-Injection/ - () https://theyhack.me/CVE-2025-34227-Nagios-XI-Wizard-Command-Injection/ - Exploit, Third Party Advisory
References () https://www.nagios.com/changelog/ - () https://www.nagios.com/changelog/ - Release Notes
References () https://www.nagios.com/products/security/ - () https://www.nagios.com/products/security/ - Vendor Advisory
References () https://www.vulncheck.com/advisories/nagios-xi-config-wizard-auth-command-injection - () https://www.vulncheck.com/advisories/nagios-xi-config-wizard-auth-command-injection - Third Party Advisory

14 Oct 2025, 13:15

Type Values Removed Values Added
References
  • () https://theyhack.me/CVE-2025-34227-Nagios-XI-Wizard-Command-Injection/ -

25 Sep 2025, 19:15

Type Values Removed Values Added
References
  • () https://www.vulncheck.com/advisories/nagios-xi-config-wizard-auth-command-injection -

25 Sep 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-25 17:15

Updated : 2025-10-14 19:53


NVD link : CVE-2025-34227

Mitre link : CVE-2025-34227

CVE.ORG link : CVE-2025-34227


JSON object : View

Products Affected

nagios

  • nagios_xi
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')