CVE-2025-44823
Nagios Log Server vulnerability analysis and mitigation

Overview

CVE-2025-44823 is an information disclosure vulnerability in Nagios Log Server that allows authenticated users to retrieve cleartext administrative API keys via the /nagioslogserver/index.php/api/system/get_users API endpoint. It affects all Nagios Log Server versions before 2024R1.3.2, including 2024-r1, 2024-r1.0.1, 2024-r1.0.2, 2024-r1.1, 2024-r1.2, 2024-r1.3, and 2024-r1.3.1. The vulnerability was published on October 7, 2025, and is tracked internally as GL:NLS#475. It carries a CVSS v3.1 base score of 8.8 (High) (Feedly, SecurityOnline).

Technical details

The root cause is classified as CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere). The vulnerable API endpoint /nagioslogserver/index.php/api/system/get_users returns user data including administrative API keys in cleartext, without restricting this sensitive output to privileged roles. Any authenticated user — regardless of their privilege level — can issue a GET request to this endpoint and receive administrative credentials in the response. Technical write-ups and a proof-of-concept are publicly available on Exploit-DB and GitHub (Feedly, Exploit-DB, GitHub PoC).

Impact

Successful exploitation allows an authenticated attacker with low privileges to obtain cleartext administrative API keys, which can then be used to escalate privileges and achieve full administrative control over the Nagios Log Server. This impacts confidentiality (exposure of sensitive credentials), integrity (unauthorized configuration changes or data manipulation), and availability (potential disruption of log monitoring services). Because Nagios Log Server is typically deployed as a centralized log aggregation platform, compromise could expose log data from across the monitored infrastructure and facilitate lateral movement (Feedly, ZeroPath).

Exploitability

Public proof-of-concept exploits are available on Exploit-DB (added November 6, 2025) and GitHub (added March 2, 2026), lowering the barrier to exploitation significantly (Exploit-DB, GitHub PoC). The EPSS score is approximately 1.07%, indicating a moderate probability of exploitation in the wild. As of the latest available data, there is no confirmed evidence of active in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Emerging Threats released detection rules for this CVE in their October 21, 2025 ruleset update (Emerging Threats).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible Nagios Log Server instances running versions prior to 2024R1.3.2 using tools like Shodan, Censys, or internal network scanning.
  2. Obtain low-privilege credentials: Authenticate to the Nagios Log Server with any valid user account (even a low-privileged one), as the vulnerability requires only authentication, not administrative rights.
  3. Call the vulnerable API endpoint: Issue an authenticated HTTP GET request to /nagioslogserver/index.php/api/system/get_users, including the session cookie or API token obtained during login.
  4. Extract administrative API keys: Parse the JSON response, which contains cleartext administrative API keys for all users, including administrators.
  5. Escalate privileges: Use the retrieved administrative API keys to authenticate as an administrator and perform privileged actions such as modifying configurations, accessing all log data, or further compromising the system (Exploit-DB, ZeroPath).

Indicators of compromise

  • Network: Unusual or repeated HTTP GET requests to /nagioslogserver/index.php/api/system/get_users from non-administrative user accounts or unexpected source IPs; API calls using administrative keys from IP addresses not associated with administrators.
  • Logs: Web server access logs showing requests to the get_users endpoint by low-privileged user sessions; authentication events using administrative API keys from unfamiliar clients or at unusual times.
  • Application: Unexpected administrative actions (configuration changes, new user creation, log access) performed via API key authentication shortly after a get_users API call from a non-admin account.

Mitigation and workarounds

Upgrade Nagios Log Server to version 2024R1.3.2 or later, which resolves this vulnerability. As an interim workaround, restrict network-level access to the /nagioslogserver/index.php/api/system/get_users endpoint using firewall rules or web server ACLs, limiting it to only authorized administrative systems. If exposure is suspected, immediately rotate all administrative API keys after patching and review audit logs for unauthorized API calls. Monitor for suspicious API usage patterns that may indicate compromised credentials (Feedly).

Community reactions

SecurityOnline covered the vulnerability with a headline noting a CVSS score of 9.9 and the availability of a PoC, drawing community attention shortly after disclosure (SecurityOnline). GBHackers and CyberNoz also reported on the flaw, emphasizing the risk of cleartext credential exposure in a widely-used monitoring platform (GBHackers, CyberNoz). Social media discussion appeared on Bluesky and Mastodon/Infosec.exchange, with security researchers flagging the PoC availability as a significant escalation risk. Check Point also published a defense advisory for this CVE (Check Point).

Additional resources


SourceThis report was generated using AI

Related Nagios Log Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-34277CRITICAL9.4
  • Nagios Log Server logoNagios Log Server
  • cpe:2.3:a:nagios:log_server
NoNoOct 30, 2025
CVE-2025-34274CRITICAL9.3
  • Nagios Log Server logoNagios Log Server
  • cpe:2.3:a:nagios:log_server
NoNoOct 30, 2025
CVE-2025-34298HIGH8.7
  • Nagios Log Server logoNagios Log Server
  • cpe:2.3:a:nagios:log_server
NoNoOct 30, 2025
CVE-2025-34322HIGH8.6
  • Nagios Log Server logoNagios Log Server
  • cpe:2.3:a:nagios:log_server
NoNoNov 17, 2025
CVE-2025-34323HIGH8.5
  • Nagios Log Server logoNagios Log Server
  • cpe:2.3:a:nagios:log_server
NoNoNov 17, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management