CVE-2026-48553
Received Received - Intake

Authenticated Remote Code Execution in Nagios Core and Nagios XI via NRDP Macro Injection

Vulnerability report for CVE-2026-48553, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-12

Assigner: VulnCheck

Description

Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection through the Nagios Remote Data Processor (NRDP). When a custom variable defined on a host, service, or contact is referenced in a shell-executed command line, an authenticated attacker with NRDP access can inject OS commands through the macro value. Exploitation requires a non-default configuration in which a custom variable is defined and referenced in a shell-executed command.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-12
Generated
2026-08-12
AI Q&A
2026-08-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
nagios nagios_core to 4.5.13 (exc)
nagios nagios_xi to 2026R1.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-48553 is an authenticated remote code execution (RCE) vulnerability in Nagios Core before 4.5.13 and Nagios XI before 2026R1.5. It occurs via custom-variable macro injection through the Nagios Remote Data Processor (NRDP). An authenticated attacker with NRDP access can inject OS commands into a custom variable if it is referenced in a shell-executed command line. Exploitation requires a non-default configuration where a custom variable is both defined and used in such a command.

Detection Guidance

Check Nagios Core versions before 4.5.13 and Nagios XI versions before 2026R1.5 for vulnerability. Inspect NRDP configurations for custom variables referenced in shell-executed commands. Review logs for unusual command injections or unauthorized NRDP access.

Impact Analysis

This vulnerability allows an authenticated attacker with NRDP access to execute arbitrary OS commands on the Nagios server. This could lead to full system compromise, unauthorized data access, or disruption of Nagios monitoring services. The impact depends on the server's configuration and the privileges of the Nagios service.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate compliance requirements such as GDPR (data protection) or HIPAA (health information security). Organizations using vulnerable Nagios versions may face regulatory penalties if this flaw is exploited to access or leak sensitive data.

Mitigation Strategies

Upgrade Nagios Core to version 4.5.13 or later and Nagios XI to 2026R1.5 or later. Disable NRDP access for non-essential users. Audit and remove custom variables used in shell-executed commands. Monitor for suspicious activity in NRDP logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-48553. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart