CVE-2024-13986
Executive Summary
Nagios XI versions prior to 2024R1.3.2 allow attackers to upload arbitrary files and rename snapshots without proper path validation, enabling placement of malicious PHP files in a web‑accessible directory. By chaining an arbitrary file upload and a path traversal in the Core Config Snapshots interface, an attacker can execute code as the www‑data user, leading to remote code execution. The vulnerability is not yet listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 8.8 (HIGH) - Published: 2025-08-28T16:15:32.883 - Last Modified: 2026-09-26T21:10:00.130
Original Description: Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload and a path traversal in the Core Config Snapshots interface. The issue arises from insufficient validation of file paths and extensions during MIB upload and snapshot rename operations. Exploitation results in the placement of attacker-controlled PHP files in a web-accessible directory, executed as the www-data user.
"What matters is the value we've created in our lives, the people we've made happy and how much we've grown as people."
— Daisaku Ikeda