Vulnerability record · CVE-2018-8735 · published 18 April 2018
CVE-2018-8735: Nagios XI OS command injection allows remote code execution
Nagios · Nagios Xi
Nagios XI versions 5.2.x through 5.4.x before 5.4.13 contain an OS command injection flaw (CWE-78) that permits remote command execution. Because Nagios XI is a monitoring platform often run with elevated privileges and reachable from internal networks, successful exploitation can compromise the monitoring host itself.
Description
Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commands on the target system, aka OS command injection.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityA network-reachable authenticated RCE with public exploit code and very high EPSS probability warrants prompt patching despite the low-privilege requirement.
What it is
Nagios XI versions 5.2.x through 5.4.x before 5.4.13 contain an OS command injection flaw (CWE-78) that permits remote command execution. Because Nagios XI is a monitoring platform often run with elevated privileges and reachable from internal networks, successful exploitation can compromise the monitoring host itself.
Impact
An attacker can execute arbitrary commands on the target system, leading to full compromise of the Nagios XI host and any credentials or monitored systems it manages.
Attack surface
The vulnerability is network-reachable (AV:N) with low attack complexity and no user interaction, but requires low privileges (PR:L), meaning the attacker needs some authenticated access to the application.
Exploitation
CVE-2018-8735 is not listed in CISA KEV, but public exploit code exists (Exploit-DB 44560 and 44969, plus a third-party technical writeup), and EPSS shows a 30-day probability of roughly 0.64 (99th percentile), indicating high likelihood of exploitation activity.
What to do
- Upgrade Nagios XI to 5.4.13 or later, which the vendor change log identifies as the fixed release.
- Restrict network access to the Nagios XI web interface to trusted administrative networks only.
- Enforce least privilege and strong authentication for Nagios XI accounts, and audit for unnecessary low-privilege users.
- Run the Nagios XI service under a dedicated low-privilege account rather than root where feasible.
- Monitor vendor advisories and apply subsequent Nagios XI security updates promptly.
Detection
- Inspect Nagios XI web server and application logs for suspicious command or shell metacharacter patterns in request parameters.
- Monitor for unexpected child processes spawned by the Nagios XI web or application service (for example shells or system utilities).
- Alert on outbound network connections originating from the Nagios XI host to unfamiliar destinations.
- Review Nagios XI user accounts and authentication events for anomalous or newly created low-privilege users.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-8735 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-8735), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.