
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2043 is an OS command injection vulnerability in Nagios XI affecting the esensors_websensor_configwizard_func method, allowing authenticated remote attackers to execute arbitrary code in the context of the service account. The vulnerability was reported to Nagios on October 8, 2025, and publicly disclosed on February 12, 2026, via a coordinated Zero Day Initiative advisory. It affects Nagios XI version 2026-r1, with a patch available in Nagios XI 2026r1.0.1. The ZDI assigned a CVSS v3.1 score of 7.2 (High), while Feedly's estimate places it at 8.8 (High) (ZDI Advisory, Nagios Changelog).
The root cause is improper neutralization of special elements in an OS command (CWE-78), specifically within the esensors_websensor_configwizard_func method of Nagios XI. User-supplied input is passed directly to a system call without adequate sanitization or validation, enabling an attacker to inject arbitrary OS commands. Exploitation requires network access and low-privilege authentication (a valid Nagios XI account), with no user interaction needed. The vulnerability was discovered by Vladislav Berghici of Trend Research and tracked internally as ZDI-CAN-28249 (ZDI Advisory).
Successful exploitation grants an authenticated attacker arbitrary code execution on the affected Nagios XI host in the context of the service account, resulting in high confidentiality, integrity, and availability impact. An attacker could read sensitive monitoring configuration data, modify system files, disrupt monitoring services, or use the compromised host as a pivot point for lateral movement within the monitored network infrastructure. Given that Nagios XI typically has broad network visibility and credentials for monitored systems, compromise could have significant downstream consequences (ZDI Advisory, Feedly).
A proof-of-concept advisory is publicly available via the Zero Day Initiative (ZDI Advisory). As of the time of reporting, there is no confirmed evidence of active in-the-wild exploitation. The vulnerability is detectable via Tenable Nessus plugin 299396. The EPSS score is approximately 0.0117 (1.17%), indicating a relatively low but non-negligible probability of exploitation in the near term. No threat actor attribution or CISA KEV catalog listing has been identified for this CVE.
esensors_websensor_configwizard_func method, which is part of the eSensors WebSensor configuration wizard in Nagios XI.;, |, or $()) that will be passed unsanitized to a system call.;, |, `, $())/bin/bash, curl, wget, nc, python) not associated with normal monitoring tasksNagios has released a patch in Nagios XI version 2026r1.0.1 that addresses this vulnerability; administrators should upgrade immediately (Nagios Changelog). As interim mitigations, restrict network access to the Nagios XI management interface to trusted IP ranges only, and enforce the principle of least privilege for Nagios service account permissions. Monitor Nagios XI logs for suspicious authentication attempts and anomalous command execution patterns. Disable or restrict access to the eSensors WebSensor configuration wizard if it is not required in your environment.
The vulnerability was reported by Vladislav Berghici of Trend Research through the Zero Day Initiative's coordinated disclosure program, with Nagios issuing a patch prior to public disclosure (ZDI Advisory). Check Point has also published a defense advisory referencing this CVE (Check Point Advisory). No significant broader community or social media discussion has been identified beyond standard vulnerability database aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."