← Vulnerability feed

Vulnerability record · CVE-2020-5792 · published 20 October 2020

CVE-2020-5792: Nagios XI argument injection enables arbitrary file write and code execution

Nagios · Nagios Xi

Nagios XI 5.7.3 fails to neutralize argument delimiters in a command, allowing an authenticated admin to inject arguments. This lets the attacker write to arbitrary files and ultimately execute code as the apache user.

7.2 CVSS 3.1 High EPSS 59% · top 0.9% CWE-88 · Argument injection
7.2CVSS 3.1 base score, v2 6.5
59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitrary files and ultimately execute code with the privileges of the apache user.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCVSS 7.2 with high confidentiality, integrity and availability impact, public exploit code, and very high EPSS, though exploitation requires an authenticated admin account.

What it is

Nagios XI 5.7.3 fails to neutralize argument delimiters in a command, allowing an authenticated admin to inject arguments. This lets the attacker write to arbitrary files and ultimately execute code as the apache user.

Impact

An attacker gains arbitrary file write and remote code execution with the privileges of the apache user. This can lead to full compromise of the Nagios XI host and any data or credentials it holds.

Attack surface

Reachable over the network via the Nagios XI web interface; the CVSS vector requires high privileges (PR:H) and no user interaction (UI:N). The attacker must already hold an authenticated admin account.

Exploitation

Public exploit code is referenced by Packet Storm and Tenable, and EPSS is 0.60966 (99.1st percentile), indicating high likelihood of exploitation. It is not listed in CISA KEV and no ransomware groups are documented using it.

What to do

  • Upgrade Nagios XI to a version later than 5.7.3 that fixes the argument injection.
  • Restrict admin accounts to the minimum necessary personnel and enforce strong authentication.
  • Limit network exposure of the Nagios XI web interface to trusted management networks.
  • Monitor and audit admin-level actions for unexpected command or file operations.

Detection

  • Review Nagios XI web server and application logs for admin requests containing shell metacharacters or unexpected argument delimiters.
  • Monitor for new or modified files in web-accessible directories and other paths writable by the apache user.
  • Alert on child processes spawned by the Nagios XI web server (apache) that are not part of normal operation.
  • Track use of admin accounts outside normal working hours or from unusual source IPs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-5792 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-25296Nagios XI Windows WMI Config Wizard OS Command InjectionNagios XI 5.7.5 fails to sanitize authenticated user input in the windowswmi config wizard file, allowing OS command injection. Because the affected …KEVEPSS 72%analysed8.8CVE-2021-25297Nagios XI switch config wizard OS command injectionNagios XI 5.7.5 fails to sanitize authenticated user input in the switch configuration wizard file switch.inc.php, allowing OS command injection via …KEVEPSS 57%analysed8.8CVE-2021-25298Nagios XI cloud-vm config wizard OS command injectionNagios XI 5.7.5 fails to properly sanitize authenticated user input in /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php, all…KEVEPSS 75%analysed8.8CVE-2019-15949Nagios XI getprofile.sh command injection allows root code executionNagios XI before 5.6.6 runs the getprofile.sh script as root through a passwordless sudo entry when a system profile is downloaded. Because that scri…KEVEPSS 77%analysed9.8CVE-2024-24401Nagios XI monitoringwizard.php SQL injection allows remote code executionNagios XI 2024R1.01 contains a SQL injection flaw in the monitoringwizard.php component. A remote attacker can send a crafted payload that leads to a…EPSS 46%analysed9.8CVE-2024-24402Nagios xi improper privilege management vulnerabilityAn issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.EPSS 3.4%9.8CVE-2023-48085Nagios XI command_test.php remote code executionNagios XI before 5.11.3 contains a remote code execution flaw in the command_test.php component, classified as code injection (CWE-94). The CVSS 3.1 …EPSS 76%analysed9.8CVE-2023-48084Nagios xi sql injection vulnerabilityNagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.EPSS 34%

Source: NIST National Vulnerability Database (record CVE-2020-5792), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.