Source: nagios4 Version: 4.5.12+ds-1 Severity: grave Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for nagios4. CVE-2026-48549[0]: | Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a | CSRF vulnerability in cmd.cgi. When no Cookie header is present, the | double-submit cookie protection can be bypassed by supplying | matching NagFormId and nagFormId values in the POST body, allowing a | cross-site request to execute Nagios commands as a currently | authenticated user. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-48549 https://www.cve.org/CVERecord?id=CVE-2026-48549 Please adjust the affected versions in the BTS as needed. There is not much information available for this CVE, sait to be fixed in 4.5.13. Regards, Salvatore

