CVE-2024-13986

Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload and a path traversal in the Core Config Snapshots interface. The issue arises from insufficient validation of file paths and extensions during MIB upload and snapshot rename operations. Exploitation results in the placement of attacker-controlled PHP files in a web-accessible directory, executed as the www-data user.
CVSS

No CVSS.

Configurations

No configuration.

History

28 Aug 2025, 19:15

Type Values Removed Values Added
References
  • () https://theyhack.me/Nagios-XI-Authenticated-RCE/ -

28 Aug 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-28 16:15

Updated : 2025-08-29 16:24


NVD link : CVE-2024-13986

Mitre link : CVE-2024-13986

CVE.ORG link : CVE-2024-13986


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-434

Unrestricted Upload of File with Dangerous Type