Nagios XI versions prior to 2024R1.2 containĀ a privilege escalation vulnerability related to NagVis configuration handling (nagvis.conf). An authenticated user could manipulate NagVis configuration data or leverage insufficiently validated configuration settings to obtain elevated privileges on the Nagios XI system.
References
| Link | Resource |
|---|---|
| https://www.nagios.com/changelog/nagios-xi/ | Release Notes |
| https://www.nagios.com/products/security/#nagios-xi | Vendor Advisory |
| https://www.vulncheck.com/advisories/nagios-xi-privilege-escalation-via-nagvis-configuration | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
06 Nov 2025, 16:08
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-30 22:15
Updated : 2025-11-06 16:08
NVD link : CVE-2024-14004
Mitre link : CVE-2024-14004
CVE.ORG link : CVE-2024-14004
JSON object : View
Products Affected
nagios
- nagios_xi
CWE
CWE-269
Improper Privilege Management
