← Vulnerability feed

Vulnerability record · CVE-2018-8736 · published 18 April 2018

CVE-2018-8736: Nagios XI privilege escalation to root via RCE

Nagios · Nagios Xi

Nagios XI versions 5.2.x through 5.4.x before 5.4.13 contain a privilege escalation flaw that lets an attacker leverage an existing remote code execution vulnerability to gain root. Because the escalation builds on RCE, a foothold in the application can be turned into full control of the underlying host. The record does not specify the exact escalation mechanism or the CWE.

8.8 CVSS 3.0 High EPSS 46% · top 1.2%
8.8CVSS 3.0 base score, v2 9.0
46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RCE vulnerability escalating to root.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityCVSS 8.8 with network reachability, low privileges required, and public exploit code, though it requires an existing RCE foothold and is not in KEV.

What it is

Nagios XI versions 5.2.x through 5.4.x before 5.4.13 contain a privilege escalation flaw that lets an attacker leverage an existing remote code execution vulnerability to gain root. Because the escalation builds on RCE, a foothold in the application can be turned into full control of the underlying host. The record does not specify the exact escalation mechanism or the CWE.

Impact

An attacker who already has code execution in Nagios XI can escalate to root, gaining full control of the monitoring server and any credentials or managed hosts it holds. This can expose the entire monitored environment to further compromise.

Attack surface

The CVSS vector is network-reachable (AV:N) with low privileges required (PR:L) and no user interaction (UI:N), so an attacker with an authenticated low-privileged account can reach it remotely. The description ties it to an RCE vulnerability, meaning the escalation is chained after initial code execution.

Exploitation

CISA KEV does not list this CVE, but EPSS is high at roughly 0.46 (98.8th percentile) and multiple references are tagged Exploit, including Exploit-DB entries 44560 and 44969, indicating public exploit code exists.

What to do

  • Upgrade Nagios XI to 5.4.13 or later, which is the fixed version named in the advisory.
  • Restrict network access to the Nagios XI web interface to trusted management networks only.
  • Audit and minimize Nagios XI accounts, removing unnecessary low-privileged users that could be used as the escalation starting point.
  • Patch or mitigate the underlying RCE vulnerability that this escalation depends on, since the chain requires it.
  • Run the Nagios XI service under a least-privileged account and monitor for unexpected root-level process creation.

Detection

  • Monitor for new processes spawned by the Nagios XI web or service account that run as root or use setuid binaries.
  • Alert on unexpected outbound connections or command execution originating from the Nagios XI host.
  • Review Nagios XI audit and web logs for exploitation attempts against known RCE endpoints preceding privilege escalation.
  • Watch for changes to root-owned files, cron jobs, or systemd units on the Nagios XI server.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXT Release NotesVendor Advisory
https://blog.redactedsec.net/exploits/2018/04/26/nagios.html ExploitRelease NotesTechnical DescriptionThird Party Advisory
https://gist.github.com/caleBot/f0a93b5a98574393e0139104eacc2d0f Third Party Advisory
https://www.exploit-db.com/exploits/44560/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/44969/ ExploitThird Party AdvisoryVDB Entry
https://www.nagios.com/downloads/nagios-xi/change-log/ Release NotesVendor Advisory
https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXT Release NotesVendor Advisory
https://blog.redactedsec.net/exploits/2018/04/26/nagios.html ExploitRelease NotesTechnical DescriptionThird Party Advisory
https://gist.github.com/caleBot/f0a93b5a98574393e0139104eacc2d0f Third Party Advisory
https://www.exploit-db.com/exploits/44560/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/44969/ ExploitThird Party AdvisoryVDB Entry
https://www.nagios.com/downloads/nagios-xi/change-log/ Release NotesVendor Advisory

Track CVE-2018-8736 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-25296Nagios XI Windows WMI Config Wizard OS Command InjectionNagios XI 5.7.5 fails to sanitize authenticated user input in the windowswmi config wizard file, allowing OS command injection. Because the affected …KEVEPSS 72%analysed8.8CVE-2021-25297Nagios XI switch config wizard OS command injectionNagios XI 5.7.5 fails to sanitize authenticated user input in the switch configuration wizard file switch.inc.php, allowing OS command injection via …KEVEPSS 57%analysed8.8CVE-2021-25298Nagios XI cloud-vm config wizard OS command injectionNagios XI 5.7.5 fails to properly sanitize authenticated user input in /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php, all…KEVEPSS 75%analysed8.8CVE-2019-15949Nagios XI getprofile.sh command injection allows root code executionNagios XI before 5.6.6 runs the getprofile.sh script as root through a passwordless sudo entry when a system profile is downloaded. Because that scri…KEVEPSS 77%analysed9.8CVE-2024-24401Nagios XI monitoringwizard.php SQL injection allows remote code executionNagios XI 2024R1.01 contains a SQL injection flaw in the monitoringwizard.php component. A remote attacker can send a crafted payload that leads to a…EPSS 46%analysed9.8CVE-2024-24402Nagios xi improper privilege management vulnerabilityAn issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.EPSS 3.4%9.8CVE-2023-48085Nagios XI command_test.php remote code executionNagios XI before 5.11.3 contains a remote code execution flaw in the command_test.php component, classified as code injection (CWE-94). The CVSS 3.1 …EPSS 76%analysed9.8CVE-2023-48084Nagios xi sql injection vulnerabilityNagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.EPSS 34%

Source: NIST National Vulnerability Database (record CVE-2018-8736), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.