Answer in brief
CVE-2026-48549 records a Medium severity (CVSS 6.5) vulnerability in Nagios Core / XI CSRF via cmd.cgi Double-Submit Cookie. The current sources do not mark it as known exploited. The current feed maps Nagios Enterprises, LLC./Nagios Core (generic), Nagios Enterprises, LLC./Nagios Core (generic), Nagios Enterprises, LLC./Nagios XI (generic), Nagios Enterprises, LLC./Nagios XI (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 6.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Nagios Enterprises, LLC./Nagios Core (generic), Nagios Enterprises, LLC./Nagios Core (generic), Nagios Enterprises, LLC./Nagios XI (generic), Nagios Enterprises, LLC./Nagios XI (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Nagios Enterprises, LLC./Nagios Coregeneric | >=0 <4.5.13 | 4.5.13 |
| Nagios Enterprises, LLC./Nagios Coregeneric | * | Not reported |
| Nagios Enterprises, LLC./Nagios XIgeneric | >=0 <2026R1.5 | 2026R1.5 |
| Nagios Enterprises, LLC./Nagios XIgeneric | * | Not reported |
Published upstream
Aug 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 26, 2026
Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSRF vulnerability in cmd.cgi. When no Cookie header is present, the double-submit cookie protection can be bypassed by supplying matching NagFormId and nagFormId values in the POST body, allowing a cross-site request to execute Nagios commands as a currently authenticated user.
Quoted source text, attributed separately from HOL analysis.