
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-44823 is an information disclosure vulnerability in Nagios Log Server that allows authenticated users to retrieve cleartext administrative API keys via the /nagioslogserver/index.php/api/system/get_users API endpoint. It affects all Nagios Log Server versions before 2024R1.3.2, including 2024-r1, 2024-r1.0.1, 2024-r1.0.2, 2024-r1.1, 2024-r1.2, 2024-r1.3, and 2024-r1.3.1. The vulnerability was published on October 7, 2025, and is tracked internally as GL:NLS#475. It carries a CVSS v3.1 base score of 8.8 (High) (Feedly, SecurityOnline).
The root cause is classified as CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere). The vulnerable API endpoint /nagioslogserver/index.php/api/system/get_users returns user data including administrative API keys in cleartext, without restricting this sensitive output to privileged roles. Any authenticated user — regardless of their privilege level — can issue a GET request to this endpoint and receive administrative credentials in the response. Technical write-ups and a proof-of-concept are publicly available on Exploit-DB and GitHub (Feedly, Exploit-DB, GitHub PoC).
Successful exploitation allows an authenticated attacker with low privileges to obtain cleartext administrative API keys, which can then be used to escalate privileges and achieve full administrative control over the Nagios Log Server. This impacts confidentiality (exposure of sensitive credentials), integrity (unauthorized configuration changes or data manipulation), and availability (potential disruption of log monitoring services). Because Nagios Log Server is typically deployed as a centralized log aggregation platform, compromise could expose log data from across the monitored infrastructure and facilitate lateral movement (Feedly, ZeroPath).
Public proof-of-concept exploits are available on Exploit-DB (added November 6, 2025) and GitHub (added March 2, 2026), lowering the barrier to exploitation significantly (Exploit-DB, GitHub PoC). The EPSS score is approximately 1.07%, indicating a moderate probability of exploitation in the wild. As of the latest available data, there is no confirmed evidence of active in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Emerging Threats released detection rules for this CVE in their October 21, 2025 ruleset update (Emerging Threats).
/nagioslogserver/index.php/api/system/get_users, including the session cookie or API token obtained during login./nagioslogserver/index.php/api/system/get_users from non-administrative user accounts or unexpected source IPs; API calls using administrative keys from IP addresses not associated with administrators.get_users endpoint by low-privileged user sessions; authentication events using administrative API keys from unfamiliar clients or at unusual times.get_users API call from a non-admin account.Upgrade Nagios Log Server to version 2024R1.3.2 or later, which resolves this vulnerability. As an interim workaround, restrict network-level access to the /nagioslogserver/index.php/api/system/get_users endpoint using firewall rules or web server ACLs, limiting it to only authorized administrative systems. If exposure is suspected, immediately rotate all administrative API keys after patching and review audit logs for unauthorized API calls. Monitor for suspicious API usage patterns that may indicate compromised credentials (Feedly).
SecurityOnline covered the vulnerability with a headline noting a CVSS score of 9.9 and the availability of a PoC, drawing community attention shortly after disclosure (SecurityOnline). GBHackers and CyberNoz also reported on the flaw, emphasizing the risk of cleartext credential exposure in a widely-used monitoring platform (GBHackers, CyberNoz). Social media discussion appeared on Bluesky and Mastodon/Infosec.exchange, with security researchers flagging the PoC availability as a significant escalation risk. Check Point also published a defense advisory for this CVE (Check Point).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."