#1144495 nagios4: CVE-2026-48550 CVE-2026-48551 CVE-2026-48552 CVE-2026-48553 CVE-2026-48554

Package:
src:nagios4
Source:
src:nagios4
Submitter:
Salvatore Bonaccorso
Date:
2026-08-16 07:13:02 UTC
Severity:
normal
Tags:
#1144495#5
Date:
2026-08-16 07:11:55 UTC
From:
To:
Hi,

The following vulnerabilities were published for nagios4.

CVE-2026-48550[0]:
| Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are
| vulnerable to reflected cross-site scripting in cmd.cgi via the
| NagFormId parameter. An unauthenticated remote attacker can craft a
| malicious link that, when followed by an authenticated user,
| executes arbitrary JavaScript in the victim's browser.


CVE-2026-48551[1]:
| Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a
| cross-site request forgery protection bypass via a self-supplied
| double-submit cookie. An attacker can supply matching cookie and
| request parameter values to bypass CSRF protection, enabling
| unauthenticated attackers to run commands as authorized users via
| malicious links.


CVE-2026-48552[2]:
| Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are
| vulnerable to DOM-based cross-site scripting in jsonquery.js.
| Unencoded JSON string values reflected from stored fields are
| inserted into the DOM without sanitization, allowing attackers to
| run arbitrary JavaScript in the victim's browser.


CVE-2026-48553[3]:
| Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are
| vulnerable to authenticated remote code execution via custom-
| variable macro injection through the Nagios Remote Data Processor
| (NRDP). When a custom variable defined on a host, service, or
| contact is referenced in a shell-executed command line, an
| authenticated attacker with NRDP access can inject OS commands
| through the macro value. Exploitation requires a non-default
| configuration in which a custom variable is defined and referenced
| in a shell-executed command.


CVE-2026-48554[4]:
| Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are
| vulnerable to authenticated remote code execution via unfiltered
| NOTIFICATION-family macro substitution through the com_data
| parameter. When a notification command references
| $NOTIFICATIONCOMMENT$ or $NOTIFICATIONAUTHOR$ in a shell-reachable
| position, authenticated UI users can run arbitrary commands as the
| nagios user. Exploitation requires a non-default configuration in
| which a notification command references these macros in a shell-
| executed command line.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-48550
https://www.cve.org/CVERecord?id=CVE-2026-48550
[1] https://security-tracker.debian.org/tracker/CVE-2026-48551
https://www.cve.org/CVERecord?id=CVE-2026-48551
[2] https://security-tracker.debian.org/tracker/CVE-2026-48552
https://www.cve.org/CVERecord?id=CVE-2026-48552
[3] https://security-tracker.debian.org/tracker/CVE-2026-48553
https://www.cve.org/CVERecord?id=CVE-2026-48553
[4] https://security-tracker.debian.org/tracker/CVE-2026-48554
https://www.cve.org/CVERecord?id=CVE-2026-48554

Regards,
Salvatore