#1145888 nagios4: CVE-2026-48549

Package:
src:nagios4
Source:
src:nagios4
Submitter:
Salvatore Bonaccorso
Date:
2026-08-27 14:37:02 UTC
Severity:
normal
Tags:
#1145888#5
Date:
2026-08-27 14:34:14 UTC
From:
To:
Hi,

The following vulnerability was published for nagios4.

CVE-2026-48549[0]:
| Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a
| CSRF vulnerability in cmd.cgi. When no Cookie header is present, the
| double-submit cookie protection can be bypassed by supplying
| matching NagFormId and nagFormId values in the POST body, allowing a
| cross-site request to execute Nagios commands as a currently
| authenticated user.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-48549
https://www.cve.org/CVERecord?id=CVE-2026-48549

Please adjust the affected versions in the BTS as needed.

There is not much information available for this CVE, sait to be fixed
in 4.5.13.

Regards,
Salvatore