
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67255 is a SQL Injection vulnerability in Nagios XI 2026R1.0.1 (build 1762361101) that allows any authenticated user to exploit improperly filtered Dashboard parameters to execute arbitrary SQL commands. The vulnerability was published on December 29, 2025, and classified under CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). It carries a CVSS v3.1 base score of 8.8 (High), reflecting network-based exploitation with low privileges required and no user interaction needed (Red Hat CVE, ENISA EUVD).
The root cause is insufficient input validation and filtering of Dashboard-related parameters in Nagios XI 2026R1.0.1, classified as CWE-89 (SQL Injection). An authenticated attacker can craft malicious SQL payloads within Dashboard parameters that are passed directly to the underlying database without proper sanitization or parameterized queries. The attack vector is network-based, requires only low-level authenticated access, and has low attack complexity, making it straightforward to exploit. A public GitHub repository referencing this vulnerability has been identified at YongYe-Security/NagiosXI, though detailed PoC content was not available at time of reporting.
Successful exploitation grants an attacker high impact across confidentiality, integrity, and availability — allowing unauthorized read access to sensitive database contents (e.g., credentials, monitoring configurations, host/service data), modification or deletion of database records, and potential disruption of the Nagios XI monitoring service. Given Nagios XI's role as a network monitoring platform, database compromise could expose credentials and infrastructure details that facilitate lateral movement across the monitored environment (Red Hat CVE, ENISA EUVD).
No confirmed in-the-wild exploitation has been reported as of the time of this report. The EPSS score is approximately 0.014% (0.000140), indicating a currently low probability of exploitation in the near term. No CISA KEV catalog listing has been identified. A GitHub repository (YongYe-Security/NagiosXI) is referenced in the vulnerability disclosure, suggesting researcher-level PoC or proof-of-concept material may exist, but no weaponized exploit kit usage has been documented (ENISA EUVD, YongYe-Security/NagiosXI).
' OR 1=1-- or using UNION-based payloads to enumerate database tables.', --, UNION, SELECT, OR 1=1) in parameter values.nagios, xi_users, xi_options); unusual SELECT or UNION statements originating from the web application user.Nagios has not publicly announced a patched version at the time of this report; users should monitor the Nagios official site for security updates addressing CVE-2025-67255. As an interim measure, restrict access to the Nagios XI web interface to trusted IP addresses using firewall rules or network segmentation, and enforce the principle of least privilege for all Nagios XI user accounts. Organizations should also consider enabling a Web Application Firewall (WAF) with SQL injection detection rules in front of the Nagios XI instance until an official patch is available (Red Hat CVE, ENISA EUVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."