Vulnerability record · CVE-2019-9164 · published 28 March 2019
CVE-2019-9164: Nagios XI authenticated command injection via autodiscovery job
Nagios · Nagios Xi
Nagios XI before 5.5.11 allows an authenticated user to execute arbitrary remote commands through a new autodiscovery job. The flaw is a command injection reachable over the network, and the record also carries a CWE-79 cross-site scripting label that conflicts with the described command injection. It matters because a low-privileged account can turn into full remote code execution on a monitoring server that often holds broad infrastructure access.
Description
Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a new autodiscovery job.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with low-privilege authenticated remote code execution and public exploit references, though not in KEV and requiring a valid account.
What it is
Nagios XI before 5.5.11 allows an authenticated user to execute arbitrary remote commands through a new autodiscovery job. The flaw is a command injection reachable over the network, and the record also carries a CWE-79 cross-site scripting label that conflicts with the described command injection. It matters because a low-privileged account can turn into full remote code execution on a monitoring server that often holds broad infrastructure access.
Impact
An attacker with a valid Nagios XI account gains arbitrary command execution on the server, with high impact to confidentiality, integrity and availability. That can lead to credential theft, lateral movement into monitored systems, or tampering with alerting.
Attack surface
Reached over the network through the Nagios XI web interface by creating an autodiscovery job. Authentication is required at low privilege (PR:L); no user interaction is needed (UI:N).
Exploitation
Not listed in CISA KEV, but EPSS is 0.45972 (98.75th percentile) and multiple references are tagged Exploit, indicating public exploit material exists. No ransomware group use is documented.
What to do
- Upgrade Nagios XI to 5.5.11 or later, per the vendor change log and security page.
- Restrict access to the Nagios XI web interface to trusted networks or administrative jump hosts.
- Review and minimize accounts with permission to create autodiscovery jobs; apply least privilege.
- Audit existing autodiscovery jobs and remove any that are unnecessary or unexpected.
- Monitor Nagios XI hosts for unexpected outbound connections and child processes spawned by the web stack.
Detection
- Alert on new or modified autodiscovery jobs, especially those created outside change windows.
- Monitor web server and Nagios XI process trees for shell or command interpreter children.
- Review Nagios XI logs for anomalous job creation and command execution patterns from low-privileged accounts.
- Watch for outbound connections from the Nagios XI host to unfamiliar destinations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/152496/Nagios-XI-5.5.10-XSS-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2019/Apr/19 | ExploitMailing ListThird Party Advisory |
| https://www.nagios.com/downloads/nagios-xi/change-log/ | Release NotesVendor Advisory |
| https://www.nagios.com/products/security/ | Vendor Advisory |
| http://packetstormsecurity.com/files/152496/Nagios-XI-5.5.10-XSS-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2019/Apr/19 | ExploitMailing ListThird Party Advisory |
| https://www.nagios.com/downloads/nagios-xi/change-log/ | Release NotesVendor Advisory |
| https://www.nagios.com/products/security/ | Vendor Advisory |
Track CVE-2019-9164 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-9164), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.