← Vulnerability feed

Vulnerability record · CVE-2019-15949 · published 5 September 2019

CVE-2019-15949: Nagios XI getprofile.sh command injection allows root code execution

Nagios · Nagios Xi

Nagios XI before 5.6.6 runs the getprofile.sh script as root through a passwordless sudo entry when a system profile is downloaded. Because that script executes check_plugin, which is owned by the nagios user, anyone who can modify plugins through the web interface or who holds the nagios account on the server can insert commands that run as root. This turns a low-privilege foothold into full root compromise of the monitoring server.

8.8 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 77% · top 0.5% CWE-78 · OS command injection
8.8CVSS 3.1 base score, v2 9.0
77%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The getprofile.sh script, invoked by downloading a system profile (profile.php?cmd=download), is executed as root via a passwordless sudo entry; the script executes check_plugin, which is owned by the nagios user. A user logged into Nagios XI with permissions to modify plugins, or the nagios user on the server, can modify the check_plugin executable and insert malicious commands to execute as root.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityA remotely reachable, authenticated flaw that yields root code execution, is in CISA KEV, and has very high EPSS probability with public exploits.

What it is

Nagios XI before 5.6.6 runs the getprofile.sh script as root through a passwordless sudo entry when a system profile is downloaded. Because that script executes check_plugin, which is owned by the nagios user, anyone who can modify plugins through the web interface or who holds the nagios account on the server can insert commands that run as root. This turns a low-privilege foothold into full root compromise of the monitoring server.

Impact

An attacker with plugin-modification rights or the nagios local account gains arbitrary command execution as root, giving complete control of the Nagios XI host and any credentials or monitored systems it manages.

Attack surface

Reached over the network through the Nagios XI web interface (profile.php?cmd=download) or via local access as the nagios user. It requires authentication with plugin-modification permissions or the nagios account; no user interaction beyond triggering the profile download is needed.

Exploitation

Listed in CISA KEV since 2021-11-03 with a required action to patch, and EPSS 30-day probability is 0.77039 (99.5th percentile). Multiple public exploit references exist, including a dedicated GitHub root-RCE exploit, so exploitation is mature and widespread.

What to do

  • Upgrade Nagios XI to 5.6.6 or later immediately.
  • Restrict plugin-modification permissions to the smallest possible set of trusted administrators.
  • Remove or tightly scope the passwordless sudo entry that runs getprofile.sh as root.
  • Audit and lock down the nagios local account, including SSH access and file ownership of check_plugin.
  • Monitor and alert on changes to check_plugin and other plugin executables.

Detection

  • Alert on modifications to check_plugin or other plugin files owned by the nagios user.
  • Monitor web logs for profile.php?cmd=download requests, especially from unexpected accounts or IPs.
  • Audit sudo and process logs for getprofile.sh executions and child processes running as root.
  • Watch for unexpected root-level command execution or reverse shells originating from the Nagios XI host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-15949 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Nagios XI Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-15949 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-25296Nagios XI Windows WMI Config Wizard OS Command InjectionNagios XI 5.7.5 fails to sanitize authenticated user input in the windowswmi config wizard file, allowing OS command injection. Because the affected …KEVEPSS 72%analysed8.8CVE-2021-25297Nagios XI switch config wizard OS command injectionNagios XI 5.7.5 fails to sanitize authenticated user input in the switch configuration wizard file switch.inc.php, allowing OS command injection via …KEVEPSS 57%analysed8.8CVE-2021-25298Nagios XI cloud-vm config wizard OS command injectionNagios XI 5.7.5 fails to properly sanitize authenticated user input in /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php, all…KEVEPSS 75%analysed9.8CVE-2024-24401Nagios XI monitoringwizard.php SQL injection allows remote code executionNagios XI 2024R1.01 contains a SQL injection flaw in the monitoringwizard.php component. A remote attacker can send a crafted payload that leads to a…EPSS 46%analysed9.8CVE-2024-24402Nagios xi improper privilege management vulnerabilityAn issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.EPSS 3.4%9.8CVE-2023-48085Nagios XI command_test.php remote code executionNagios XI before 5.11.3 contains a remote code execution flaw in the command_test.php component, classified as code injection (CWE-94). The CVSS 3.1 …EPSS 76%analysed9.8CVE-2023-48084Nagios xi sql injection vulnerabilityNagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.EPSS 34%9.8CVE-2022-38250Nagios xi sql injection vulnerabilityNagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page.EPSS 3.0%

Source: NIST National Vulnerability Database (record CVE-2019-15949), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.