Bug#1144495: nagios4: CVE-2026-48550 CVE-2026-48551 CVE-2026-48552 CVE-2026-48553 CVE-2026-48554
Salvatore Bonaccorso <[email protected]>
| Newsgroups | gmane.linux.debian.devel.bugs.rc |
|---|---|
| Message-ID | <178686431596.1969682.14360977179914640724.reportbug__3551.89360432036$1786864397$gmane$org@eldamar.lan> |
Source: nagios4 Version: 4.5.12+ds-1 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]> Hi, The following vulnerabilities were published for nagios4. CVE-2026-48550[0]: | Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are | vulnerable to reflected cross-site scripting in cmd.cgi via the | NagFormId parameter. An unauthenticated remote attacker can craft a | malicious link that, when followed by an authenticated user, | executes arbitrary JavaScript in the victim's browser. CVE-2026-48551[1]: | Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a | cross-site request forgery protection bypass via a self-supplied | double-submit cookie. An attacker can supply matching cookie and | request parameter values to bypass CSRF protection, enabling | unauthenticated attackers to run commands as authorized users via | malicious links. CVE-2026-48552[2]: | Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are | vulnerable to DOM-based cross-site scripting in jsonquery.js. | Unencoded JSON string values reflected from stored fields are | inserted into the DOM without sanitization, allowing attackers to | run arbitrary JavaScript in the victim's browser. CVE-2026-48553[3]: | Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are | vulnerable to authenticated remote code execution via custom- | variable macro injection through the Nagios Remote Data Processor | (NRDP). When a custom variable defined on a host, service, or | contact is referenced in a shell-executed command line, an | authenticated attacker with NRDP access can inject OS commands | through the macro value. Exploitation requires a non-default | configuration in which a custom variable is defined and referenced | in a shell-executed command. CVE-2026-48554[4]: | Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are | vulnerable to authenticated remote code execution via unfiltered | NOTIFICATION-family macro substitution through the com_data | parameter. When a notification command references | $NOTIFICATIONCOMMENT$ or $NOTIFICATIONAUTHOR$ in a shell-reachable | position, authenticated UI users can run arbitrary commands as the | nagios user. Exploitation requires a non-default configuration in | which a notification command references these macros in a shell- | executed command line. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-48550 https://www.cve.org/CVERecord?id=CVE-2026-48550 [1] https://security-tracker.debian.org/tracker/CVE-2026-48551 https://www.cve.org/CVERecord?id=CVE-2026-48551 [2] https://security-tracker.debian.org/tracker/CVE-2026-48552 https://www.cve.org/CVERecord?id=CVE-2026-48552 [3] https://security-tracker.debian.org/tracker/CVE-2026-48553 https://www.cve.org/CVERecord?id=CVE-2026-48553 [4] https://security-tracker.debian.org/tracker/CVE-2026-48554 https://www.cve.org/CVERecord?id=CVE-2026-48554 Regards, Salvatore