← Vulnerability feed

Vulnerability record · CVE-2020-5791 · published 20 October 2020

CVE-2020-5791: Nagios XI OS command injection in admin interface

Nagios · Nagios Xi

Nagios XI 5.7.3 fails to neutralize special elements used in an OS command, allowing an authenticated administrator to run operating system commands. Because the affected component is the monitoring server itself, successful exploitation gives an attacker a foothold on a host that typically holds broad infrastructure credentials.

7.2 CVSS 3.1 High EPSS 79% · top 0.4% CWE-78 · OS command injection
7.2CVSS 3.1 base score, v2 9.0
79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating system commands with the privileges of the apache user.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe flaw allows authenticated remote code execution on a sensitive monitoring host, and public exploit code plus a very high EPSS score make it a realistic target despite the admin privilege requirement.

What it is

Nagios XI 5.7.3 fails to neutralize special elements used in an OS command, allowing an authenticated administrator to run operating system commands. Because the affected component is the monitoring server itself, successful exploitation gives an attacker a foothold on a host that typically holds broad infrastructure credentials.

Impact

An attacker with admin access executes arbitrary OS commands as the apache user, enabling data theft, configuration tampering, or lateral movement from the monitoring server.

Attack surface

Reachable over the network through the Nagios XI web interface; the attacker must already hold an authenticated admin account, and no user interaction is required.

Exploitation

Public exploit code is referenced by Packet Storm and Tenable advisories, and EPSS is very high (0.786, 99.6th percentile), though the CVE is not listed in CISA KEV.

What to do

  • Upgrade Nagios XI past 5.7.3 to a vendor-supported release that fixes the command injection.
  • Restrict admin accounts to the minimum necessary staff and enforce strong authentication.
  • Limit network access to the Nagios XI web interface to trusted management networks.
  • Run the Nagios XI web service under a low-privilege account with no unnecessary OS permissions.
  • Monitor and review admin account activity and configuration changes for signs of abuse.

Detection

  • Alert on unexpected child processes spawned by the Nagios XI web server or apache user.
  • Audit Nagios XI admin logins and configuration changes for anomalies or off-hours activity.
  • Search web server and application logs for command-injection payload patterns in admin requests.
  • Monitor outbound connections from the Nagios XI host to unfamiliar destinations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-5791 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-25296Nagios XI Windows WMI Config Wizard OS Command InjectionNagios XI 5.7.5 fails to sanitize authenticated user input in the windowswmi config wizard file, allowing OS command injection. Because the affected …KEVEPSS 72%analysed8.8CVE-2021-25297Nagios XI switch config wizard OS command injectionNagios XI 5.7.5 fails to sanitize authenticated user input in the switch configuration wizard file switch.inc.php, allowing OS command injection via …KEVEPSS 57%analysed8.8CVE-2021-25298Nagios XI cloud-vm config wizard OS command injectionNagios XI 5.7.5 fails to properly sanitize authenticated user input in /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php, all…KEVEPSS 75%analysed8.8CVE-2019-15949Nagios XI getprofile.sh command injection allows root code executionNagios XI before 5.6.6 runs the getprofile.sh script as root through a passwordless sudo entry when a system profile is downloaded. Because that scri…KEVEPSS 77%analysed9.8CVE-2024-24401Nagios XI monitoringwizard.php SQL injection allows remote code executionNagios XI 2024R1.01 contains a SQL injection flaw in the monitoringwizard.php component. A remote attacker can send a crafted payload that leads to a…EPSS 46%analysed9.8CVE-2024-24402Nagios xi improper privilege management vulnerabilityAn issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.EPSS 3.4%9.8CVE-2023-48085Nagios XI command_test.php remote code executionNagios XI before 5.11.3 contains a remote code execution flaw in the command_test.php component, classified as code injection (CWE-94). The CVSS 3.1 …EPSS 76%analysed9.8CVE-2023-48084Nagios xi sql injection vulnerabilityNagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.EPSS 34%

Source: NIST National Vulnerability Database (record CVE-2020-5791), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.