Source: nagios4
Version: 4.5.12+ds-1
Severity: grave
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for nagios4.

CVE-2026-48549[0]:
| Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a
| CSRF vulnerability in cmd.cgi. When no Cookie header is present, the
| double-submit cookie protection can be bypassed by supplying
| matching NagFormId and nagFormId values in the POST body, allowing a
| cross-site request to execute Nagios commands as a currently
| authenticated user.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-48549
    https://www.cve.org/CVERecord?id=CVE-2026-48549

Please adjust the affected versions in the BTS as needed.

There is not much information available for this CVE, sait to be fixed
in 4.5.13.

Regards,
Salvatore

Reply via email to