Bug#1144495: nagios4: CVE-2026-48550 CVE-2026-48551 CVE-2026-48552 CVE-2026-48553 CVE-2026-48554

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <178686431596.1969682.14360977179914640724.reportbug__3551.89360432036$1786864397$gmane$org@eldamar.lan>
Source: nagios4
Version: 4.5.12+ds-1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for nagios4.

CVE-2026-48550[0]:
| Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are
| vulnerable to reflected cross-site scripting in cmd.cgi via the
| NagFormId parameter. An unauthenticated remote attacker can craft a
| malicious link that, when followed by an authenticated user,
| executes arbitrary JavaScript in the victim's browser.


CVE-2026-48551[1]:
| Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a
| cross-site request forgery protection bypass via a self-supplied
| double-submit cookie. An attacker can supply matching cookie and
| request parameter values to bypass CSRF protection, enabling
| unauthenticated attackers to run commands as authorized users via
| malicious links.


CVE-2026-48552[2]:
| Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are
| vulnerable to DOM-based cross-site scripting in jsonquery.js.
| Unencoded JSON string values reflected from stored fields are
| inserted into the DOM without sanitization, allowing attackers to
| run arbitrary JavaScript in the victim's browser.


CVE-2026-48553[3]:
| Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are
| vulnerable to authenticated remote code execution via custom-
| variable macro injection through the Nagios Remote Data Processor
| (NRDP). When a custom variable defined on a host, service, or
| contact is referenced in a shell-executed command line, an
| authenticated attacker with NRDP access can inject OS commands
| through the macro value. Exploitation requires a non-default
| configuration in which a custom variable is defined and referenced
| in a shell-executed command.


CVE-2026-48554[4]:
| Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are
| vulnerable to authenticated remote code execution via unfiltered
| NOTIFICATION-family macro substitution through the com_data
| parameter. When a notification command references
| $NOTIFICATIONCOMMENT$ or $NOTIFICATIONAUTHOR$ in a shell-reachable
| position, authenticated UI users can run arbitrary commands as the
| nagios user. Exploitation requires a non-default configuration in
| which a notification command references these macros in a shell-
| executed command line.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-48550
    https://www.cve.org/CVERecord?id=CVE-2026-48550
[1] https://security-tracker.debian.org/tracker/CVE-2026-48551
    https://www.cve.org/CVERecord?id=CVE-2026-48551
[2] https://security-tracker.debian.org/tracker/CVE-2026-48552
    https://www.cve.org/CVERecord?id=CVE-2026-48552
[3] https://security-tracker.debian.org/tracker/CVE-2026-48553
    https://www.cve.org/CVERecord?id=CVE-2026-48553
[4] https://security-tracker.debian.org/tracker/CVE-2026-48554
    https://www.cve.org/CVERecord?id=CVE-2026-48554

Regards,
Salvatore
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.