Vulnerability record · CVE-2021-3277 · published 7 June 2021
CVE-2021-3277: Nagios XI custom-includes rename flaw allows authenticated admin file upload RCE
Nagios · Nagios Xi
Nagios XI 5.7.5 and earlier fails to properly validate the rename functionality in the custom-includes component, letting authenticated administrators upload arbitrary files. Because PHP files can be uploaded, this escalates from file upload to remote code execution on the Nagios XI server.
Description
Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rename functionality in custom-includes component, which leads to remote code execution by uploading php files.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with high confidentiality, integrity and availability impact, though it requires authenticated admin access and is not known to be exploited in the wild.
What it is
Nagios XI 5.7.5 and earlier fails to properly validate the rename functionality in the custom-includes component, letting authenticated administrators upload arbitrary files. Because PHP files can be uploaded, this escalates from file upload to remote code execution on the Nagios XI server.
Impact
An attacker with admin credentials gains remote code execution on the Nagios XI host, with high impact to confidentiality, integrity and availability. This effectively turns a management account into full server compromise.
Attack surface
Reached over the network through the Nagios XI web interface, specifically the custom-includes rename functionality. The CVSS vector requires high privileges (PR:H) and no user interaction (UI:N), so a valid admin account is needed.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high at roughly 0.546 (98.9th percentile), and the only references are third-party advisories describing the issue.
What to do
- Upgrade Nagios XI to a version later than 5.7.5 that fixes the custom-includes rename validation.
- Restrict and audit administrator accounts; remove unused admin privileges and enforce strong authentication.
- Limit network access to the Nagios XI web interface to trusted management networks.
- Monitor the custom-includes directory for unexpected or newly written PHP files and remove unauthorized content.
Detection
- Alert on new or modified files in the Nagios XI custom-includes directory, especially .php files.
- Review web server and Nagios XI logs for rename or upload actions in custom-includes by admin accounts.
- Hunt for unexpected outbound connections or child processes spawned by the Nagios XI web server.
- Correlate admin logins with subsequent file writes or code execution events on the Nagios XI host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://asaf.me/2021/01/21/nagios-xi-5-7-5-remote-code-execution/ | Third Party Advisory |
| https://asaf.me/2021/01/21/nagios-xi-5-7-5-remote-code-execution/ | Third Party Advisory |
Track CVE-2021-3277 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-3277), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.