CVE-2025-67254
Nagios XI vulnerability analysis and mitigation

Overview

CVE-2025-67254 is a Directory Traversal vulnerability in Nagios XI 2026R1.0.1 (build 1762361101) affecting the /admin/coreconfigsnapshots.php endpoint. It was published on December 29, 2025, and classified under CWE-22 (Path Traversal). The vulnerability carries a CVSS v3.1 base score of 7.5 (High), exploitable remotely without authentication or user interaction (Red Hat CVE, ENISA EUVD).

Technical details

The vulnerability is rooted in improper input validation of file path parameters in /admin/coreconfigsnapshots.php, classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). An unauthenticated remote attacker can supply crafted path traversal sequences (e.g., ../../) in HTTP request parameters to escape the intended directory and access arbitrary files on the server filesystem. No authentication, special privileges, or user interaction are required for exploitation. A public proof-of-concept repository has been referenced at GitHub (GitHub PoC, ENISA EUVD).

Impact

Successful exploitation allows an unauthenticated attacker to read arbitrary files from the server filesystem, resulting in a high confidentiality impact with no integrity or availability impact. Sensitive files such as configuration files, credentials, SSH keys, or other system data accessible by the web server process could be exfiltrated. In a monitoring infrastructure context like Nagios XI, exposed credentials or configuration data could facilitate lateral movement to monitored hosts (Red Hat CVE, ENISA EUVD).

Exploitability

A public proof-of-concept repository is available on GitHub, lowering the barrier for exploitation (GitHub PoC). The EPSS score is approximately 0.38%, indicating a relatively low but non-negligible probability of exploitation in the wild in the near term. No confirmed in-the-wild exploitation, threat actor attribution, or CISA KEV catalog listing has been reported as of the available data (Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Nagios XI instances running version 2026R1.0.1 (build 1762361101) using tools like Shodan or Censys, searching for Nagios XI login pages or version banners.
  2. Identify vulnerable endpoint: Confirm the presence of the /admin/coreconfigsnapshots.php endpoint on the target Nagios XI instance.
  3. Craft traversal payload: Construct an HTTP GET or POST request to /admin/coreconfigsnapshots.php with a parameter containing path traversal sequences (e.g., ../../../../etc/passwd) to escape the intended directory.
  4. Send request: Submit the crafted request without any authentication credentials, as the vulnerability is exploitable unauthenticated.
  5. Retrieve sensitive files: Analyze the server response for the contents of the targeted file (e.g., /etc/passwd, Nagios configuration files containing credentials, or SSH private keys), and use any recovered credentials for further lateral movement (GitHub PoC, ENISA EUVD).

Indicators of compromise

  • Network: Unusual HTTP requests to /admin/coreconfigsnapshots.php containing path traversal sequences such as ../, %2e%2e%2f, or %252e%252e%252f in query parameters or POST body; requests originating from unexpected or external IP addresses.
  • Logs: Web server access logs (e.g., Apache/Nginx) showing GET or POST requests to /admin/coreconfigsnapshots.php with traversal patterns and HTTP 200 responses; repeated access attempts from a single IP in a short timeframe.
  • File System: No direct file system artifacts expected from read-only traversal, but monitor for subsequent access to sensitive files (e.g., /etc/passwd, /etc/nagios/, SSH key directories) by the web server process.

Mitigation and workarounds

Users should apply any available patches or updates from Nagios for Nagios XI 2026R1.0.1 by checking the official Nagios website. As a workaround, restrict access to the /admin/coreconfigsnapshots.php endpoint via web server configuration (e.g., IP allowlisting) to trusted administrative networks only. Additionally, ensure the Nagios XI web server process runs with the least privilege necessary to limit the scope of file access in the event of exploitation (Red Hat CVE, Nagios).

Additional resources


SourceThis report was generated using AI

Related Nagios XI vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-48554HIGH7.7
  • Nagios logoNagios
  • cpe:2.3:a:nagios:nagios_xi
NoNoAug 12, 2026
CVE-2026-48553HIGH7.7
  • Nagios logoNagios
  • cpe:2.3:a:nagios:nagios_xi
NoNoAug 12, 2026
CVE-2026-48551MEDIUM6.1
  • Nagios logoNagios
  • nagios4
NoNoAug 12, 2026
CVE-2026-48552MEDIUM5.1
  • Nagios logoNagios
  • nagios4
NoNoAug 12, 2026
CVE-2026-48550MEDIUM5.1
  • Nagios logoNagios
  • cpe:2.3:a:nagios:nagios_xi
NoNoAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management