CVE-2026-48549 - Nagios Core / XI CSRF via cmd.cgi Double-Submit Cookie

CVE ID :CVE-2026-48549
Published : Aug. 26, 2026, 4:16 p.m. | 56 minutes ago
Description :Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSRF vulnerability in cmd.cgi. When no Cookie header is present, the double-submit cookie protection can be bypassed by supplying matching NagFormId and nagFormId values in the POST body, allowing a cross-site request to execute Nagios commands as a currently authenticated user.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

from Latest Vulnerabilities https://ift.tt/n1Z7quT

Post a Comment

Previous Post Next Post