Nagios Core before 4.5.12 contains a cross-site request forgery vulnerability in cmd.cgi where the CSRF protection mechanism passes validation when the NagFormId cookie is absent. Attackers can craft a malicious cross-site POST request to execute arbitrary Nagios commands as a currently authenticated user without their knowledge or consent.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-26 16:16
Updated : 2026-08-26 18:16
NVD link : CVE-2026-48548
Mitre link : CVE-2026-48548
CVE.ORG link : CVE-2026-48548
JSON object : View
Products Affected
No product.
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
