CVE-2025-34227

Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It is possible to inject shell characters into arguments provided to the service and execute arbitrary system commands on the underlying host as the `nagios` user.
CVSS

No CVSS.

Configurations

No configuration.

History

25 Sep 2025, 19:15

Type Values Removed Values Added
References
  • () https://www.vulncheck.com/advisories/nagios-xi-config-wizard-auth-command-injection -

25 Sep 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-25 17:15

Updated : 2025-09-26 14:32


NVD link : CVE-2025-34227

Mitre link : CVE-2025-34227

CVE.ORG link : CVE-2025-34227


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')