
Cloud Vulnerability DB
A community-led vulnerabilities database
Nagios XI versions prior to 5.7.2 allow PHP files to be uploaded to the Audio Import directory and executed from that location. This vulnerability was discovered and disclosed in October 2025. The affected component is the audio import feature in Nagios XI installations before version 5.7.2. (VulnCheck)
The vulnerability stems from improper file upload restrictions in the Audio Import directory. The upload handler failed to properly validate file types and did not enforce storage outside of the webroot. Additionally, the web server configuration allowed execution of files within the upload directory. The vulnerability has been assigned a CVSS score of 8.7, indicating high severity. (VulnCheck)
An authenticated attacker with access to the audio import feature could upload malicious PHP files and execute them, leading to remote code execution with the privileges of the application service. This could potentially allow attackers to take control of the affected system. (VulnCheck)
The vulnerability has been fixed in Nagios XI version 5.7.2. Users should upgrade to this version or later to protect against this security issue. (Nagios Changelog)
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."