← Vulnerability feed

Vulnerability record · CVE-2019-9164 · published 28 March 2019

CVE-2019-9164: Nagios XI authenticated command injection via autodiscovery job

Nagios · Nagios Xi

Nagios XI before 5.5.11 allows an authenticated user to execute arbitrary remote commands through a new autodiscovery job. The flaw is a command injection reachable over the network, and the record also carries a CWE-79 cross-site scripting label that conflicts with the described command injection. It matters because a low-privileged account can turn into full remote code execution on a monitoring server that often holds broad infrastructure access.

8.8 CVSS 3.1 High EPSS 46% · top 1.2% CWE-79 · Cross-site scripting
8.8CVSS 3.1 base score, v2 6.5
46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a new autodiscovery job.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityCVSS 8.8 with low-privilege authenticated remote code execution and public exploit references, though not in KEV and requiring a valid account.

What it is

Nagios XI before 5.5.11 allows an authenticated user to execute arbitrary remote commands through a new autodiscovery job. The flaw is a command injection reachable over the network, and the record also carries a CWE-79 cross-site scripting label that conflicts with the described command injection. It matters because a low-privileged account can turn into full remote code execution on a monitoring server that often holds broad infrastructure access.

Impact

An attacker with a valid Nagios XI account gains arbitrary command execution on the server, with high impact to confidentiality, integrity and availability. That can lead to credential theft, lateral movement into monitored systems, or tampering with alerting.

Attack surface

Reached over the network through the Nagios XI web interface by creating an autodiscovery job. Authentication is required at low privilege (PR:L); no user interaction is needed (UI:N).

Exploitation

Not listed in CISA KEV, but EPSS is 0.45972 (98.75th percentile) and multiple references are tagged Exploit, indicating public exploit material exists. No ransomware group use is documented.

What to do

  • Upgrade Nagios XI to 5.5.11 or later, per the vendor change log and security page.
  • Restrict access to the Nagios XI web interface to trusted networks or administrative jump hosts.
  • Review and minimize accounts with permission to create autodiscovery jobs; apply least privilege.
  • Audit existing autodiscovery jobs and remove any that are unnecessary or unexpected.
  • Monitor Nagios XI hosts for unexpected outbound connections and child processes spawned by the web stack.

Detection

  • Alert on new or modified autodiscovery jobs, especially those created outside change windows.
  • Monitor web server and Nagios XI process trees for shell or command interpreter children.
  • Review Nagios XI logs for anomalous job creation and command execution patterns from low-privileged accounts.
  • Watch for outbound connections from the Nagios XI host to unfamiliar destinations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-9164 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-25296Nagios XI Windows WMI Config Wizard OS Command InjectionNagios XI 5.7.5 fails to sanitize authenticated user input in the windowswmi config wizard file, allowing OS command injection. Because the affected …KEVEPSS 72%analysed8.8CVE-2021-25297Nagios XI switch config wizard OS command injectionNagios XI 5.7.5 fails to sanitize authenticated user input in the switch configuration wizard file switch.inc.php, allowing OS command injection via …KEVEPSS 57%analysed8.8CVE-2021-25298Nagios XI cloud-vm config wizard OS command injectionNagios XI 5.7.5 fails to properly sanitize authenticated user input in /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php, all…KEVEPSS 75%analysed8.8CVE-2019-15949Nagios XI getprofile.sh command injection allows root code executionNagios XI before 5.6.6 runs the getprofile.sh script as root through a passwordless sudo entry when a system profile is downloaded. Because that scri…KEVEPSS 77%analysed9.8CVE-2024-24401Nagios XI monitoringwizard.php SQL injection allows remote code executionNagios XI 2024R1.01 contains a SQL injection flaw in the monitoringwizard.php component. A remote attacker can send a crafted payload that leads to a…EPSS 46%analysed9.8CVE-2024-24402Nagios xi improper privilege management vulnerabilityAn issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.EPSS 3.4%9.8CVE-2023-48085Nagios XI command_test.php remote code executionNagios XI before 5.11.3 contains a remote code execution flaw in the command_test.php component, classified as code injection (CWE-94). The CVSS 3.1 …EPSS 76%analysed9.8CVE-2023-48084Nagios xi sql injection vulnerabilityNagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.EPSS 34%

Source: NIST National Vulnerability Database (record CVE-2019-9164), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.