Hi,
The following vulnerability was published for nagios4.
CVE-2026-48549[0]:
| Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a
| CSRF vulnerability in cmd.cgi. When no Cookie header is present, the
| double-submit cookie protection can be bypassed by supplying
| matching NagFormId and nagFormId values in the POST body, allowing a
| cross-site request to execute Nagios commands as a currently
| authenticated user.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-48549
https://www.cve.org/CVERecord?id=CVE-2026-48549
Please adjust the affected versions in the BTS as needed.
There is not much information available for this CVE, sait to be fixed
in 4.5.13.
Regards,
Salvatore