#1144495 nagios4: CVE-2026-48550 CVE-2026-48551 CVE-2026-48552 CVE-2026-48553 CVE-2026-48554

Package:
src:nagios4
Source:
src:nagios4
Submitter:
Salvatore Bonaccorso
Date:
2026-10-09 11:41:08 UTC
Severity:
normal
Tags:
#1144495#5
Date:
2026-08-16 07:11:55 UTC
From:
To:
Hi,

The following vulnerabilities were published for nagios4.

CVE-2026-48550[0]:
| Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are
| vulnerable to reflected cross-site scripting in cmd.cgi via the
| NagFormId parameter. An unauthenticated remote attacker can craft a
| malicious link that, when followed by an authenticated user,
| executes arbitrary JavaScript in the victim's browser.


CVE-2026-48551[1]:
| Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a
| cross-site request forgery protection bypass via a self-supplied
| double-submit cookie. An attacker can supply matching cookie and
| request parameter values to bypass CSRF protection, enabling
| unauthenticated attackers to run commands as authorized users via
| malicious links.


CVE-2026-48552[2]:
| Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are
| vulnerable to DOM-based cross-site scripting in jsonquery.js.
| Unencoded JSON string values reflected from stored fields are
| inserted into the DOM without sanitization, allowing attackers to
| run arbitrary JavaScript in the victim's browser.


CVE-2026-48553[3]:
| Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are
| vulnerable to authenticated remote code execution via custom-
| variable macro injection through the Nagios Remote Data Processor
| (NRDP). When a custom variable defined on a host, service, or
| contact is referenced in a shell-executed command line, an
| authenticated attacker with NRDP access can inject OS commands
| through the macro value. Exploitation requires a non-default
| configuration in which a custom variable is defined and referenced
| in a shell-executed command.


CVE-2026-48554[4]:
| Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are
| vulnerable to authenticated remote code execution via unfiltered
| NOTIFICATION-family macro substitution through the com_data
| parameter. When a notification command references
| $NOTIFICATIONCOMMENT$ or $NOTIFICATIONAUTHOR$ in a shell-reachable
| position, authenticated UI users can run arbitrary commands as the
| nagios user. Exploitation requires a non-default configuration in
| which a notification command references these macros in a shell-
| executed command line.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-48550
https://www.cve.org/CVERecord?id=CVE-2026-48550
[1] https://security-tracker.debian.org/tracker/CVE-2026-48551
https://www.cve.org/CVERecord?id=CVE-2026-48551
[2] https://security-tracker.debian.org/tracker/CVE-2026-48552
https://www.cve.org/CVERecord?id=CVE-2026-48552
[3] https://security-tracker.debian.org/tracker/CVE-2026-48553
https://www.cve.org/CVERecord?id=CVE-2026-48553
[4] https://security-tracker.debian.org/tracker/CVE-2026-48554
https://www.cve.org/CVERecord?id=CVE-2026-48554

Regards,
Salvatore

#1144495#10
Date:
2026-10-09 11:39:28 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
nagios4, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1144495@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Russell Stuart <russell-debian@stuart.id.au> (supplier of updated nagios4 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 31 Aug 2026 19:35:18 +1000
Source: nagios4
Architecture: source
Version: 4.5.14+ds-1
Distribution: unstable
Urgency: high
Maintainer: Russell Stuart <russell-debian@stuart.id.au>
Changed-By: Russell Stuart <russell-debian@stuart.id.au>
Closes: 1063514 1119147 1121618 1123716 1144495 1145888
Changes:
 nagios4 (4.5.14+ds-1) unstable; urgency=high
 .
   * New upstream release (4.5.14).
   * Fixes reflected XSS in cmd.cgi via NagFormId (CVE-2026-48550),
     CSRF protection bypass via a self-supplied double-submit cookie
     (CVE-2026-48551), DOM XSS in jsonquery.js (CVE-2026-48552),
     authenticated RCE via custom-variable macro injection
     (CVE-2026-48553) and authenticated RCE via NOTIFICATION-family
     macro substitution (CVE-2026-48554).  Closes: #1144495.
   * Fixes the CSRF cookie bypass when no Cookie header is sent
     (CVE-2026-48549).  Closes: #1145888.
   * The daemon no longer contacts api.nagios.org by default, so it no
     longer segfaults parsing the reply.  Closes: #1119147.
   * Upstream 4.5.10 fixed the 64-bit time_t printf in lib/worker.c that
     made every check time land in 1970 on armhf.  Closes: #1123716.
   * Upstream 4.5.4 fixed the View Trends and View Alert Histogram links.
     Closes: #1063514.
   * Ship config.inc.php as a conffile in /etc/nagios4, symlinked into the
     htdocs directory, so paths can be overridden locally.  Closes: #1121618.
   * Make apache2 read /etc/nagios4/apache2.conf.
   * debian/watch: track upstream's GitHub tags, since SourceForge has
     carried no release since 4.5.9.
   * Rename 90_turn-off-use-authentication.path to .patch.
   * debian/rules: remove base/wpres-phash.h, include/Makefile and
     include/ignored_config.h in clean, so a second build in the same
     tree does not abort on unexpected upstream changes.
Checksums-Sha1:
 5ce88dfad6b8cff59c47b36fff45143c83094b95 2023 nagios4_4.5.14+ds-1.dsc
 62b1ccea513d50cdd4b2f71216226d17da80ba6c 1802612 nagios4_4.5.14+ds.orig.tar.xz
 c47ee33c2b95e6c519e72ed7cca16da88688dc94 23860 nagios4_4.5.14+ds-1.debian.tar.xz
 51abf1ad6bc6abce51ac88b05853b80c144756ed 10470 nagios4_4.5.14+ds-1_amd64.buildinfo
Checksums-Sha256:
 d1a6916b89267b1f13b9b25e224323d8dd6651bcb615f39f9b55b89ddad736bb 2023 nagios4_4.5.14+ds-1.dsc
 de0633bfe18ff66cf34d00a1534a832620140b2b23802feeefab16014d55544d 1802612 nagios4_4.5.14+ds.orig.tar.xz
 4f8a19055a2b4071e9e7cc8fd6fbe5c21072a10774905bd9a0b5a1eab9b693a5 23860 nagios4_4.5.14+ds-1.debian.tar.xz
 95b21b380107b1eaf6752af6f83f139b5a6067377ba83b75ab70c7b5e3eb80b5 10470 nagios4_4.5.14+ds-1_amd64.buildinfo
Files:
 d97f4df47921da61f67d659fd82d5955 2023 net optional nagios4_4.5.14+ds-1.dsc
 de659d5488dfb0084e0bbd21be4d1a94 1802612 net optional nagios4_4.5.14+ds.orig.tar.xz
 35d4f60e430d52a29e24e2250c1874a0 23860 net optional nagios4_4.5.14+ds-1.debian.tar.xz
 4e36dc84b5e8467ddc32f777a7c8e88b 10470 net optional nagios4_4.5.14+ds-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEZqiOeH6lCkTWvjmorNSfiF5UUm4FAmrIy1sACgkQrNSfiF5U
Um5k8A//eYOSHCaksdSnnslTzdOKnaYFmEkxVt13Nq6TJuUu0o9rnJSajcPS/ykh
rrZsTNEmxMujsOqpaq/uZSpD7HAftqHVzrmHkeFc+MDSjedgoSi1FawuokisWtmb
brZAj6CCVRpSbt1ShCiqvBLHpEUiachSDukFrb8satUs4aOfRmDQTVZUyDWU9q4u
VIg8BkQgHBpIVfYRms9ncrOBr4IP7yScN4+7quJXexVVqdzk4U6ClW5bpi7rTcFn
F/DPQnTiTPRwSO8CDUApExZFrhp56wfKTwJnVN95iqcVcMtq5GERiTFS3xy/uTwR
5kh9adgAeoUuWjByJrVNq41vpr7KE5hQniUhOLvK8yyl56E8apP68VUVDZklOlIr
WvwQCm+ZcTtHxpLr6wj0JelOwTnGKi7e6R7JlYI5aA1RleIrZiQ2Av4cBcBpv5lZ
8mD2VOuVglS+2Q/SxDw5dHZGaVSeM5yUPkxgu3tSGOjiwmmaNci5slvaWL9Nglb5
qdtAy6+yZ6Uf15aZ19wR3yX/66BJndIH1mDkKScMRg2iUYmYKvoh6+bd8R/rQe2N
Zxwe7ypgQwKkkSMQsU/jJOBDBHmR+Jd88ytxjmiqE0LidM1eVqMVW87+wbt2EoTU
ewK0lJM2Gv/Mdo1DyflcI8h8vb3uG9hzH8Ddalt8ck2HTq52+QU=
=0RPa
-----END PGP SIGNATURE-----