Vulnerability record · CVE-2021-38156 · published 15 September 2021
CVE-2021-38156: Nagios XI dashboard page stored XSS for admin users
Nagios · Nagios Xi
Nagios XI before 5.8.6 contains a cross-site scripting flaw in the dashboard page (/dashboards/#) that triggers when administrative users edit a dashboard. Because the affected page is used by administrators, successful exploitation can run script in a highly privileged session.
Description
In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityThe flaw requires authentication and user interaction and is rated medium by CVSS, but the very high EPSS score and public exploit references raise the practical risk.
What it is
Nagios XI before 5.8.6 contains a cross-site scripting flaw in the dashboard page (/dashboards/#) that triggers when administrative users edit a dashboard. Because the affected page is used by administrators, successful exploitation can run script in a highly privileged session.
Impact
An attacker can execute script in an authenticated administrator's browser, potentially stealing session data or performing administrative actions as that user. The scope change in the CVSS vector indicates the impact can extend beyond the vulnerable component.
Attack surface
Reached over the network via the dashboard page; the vector requires low privileges (PR:L) and user interaction (UI:R), meaning an authenticated user must be involved and an admin must interact with the crafted dashboard content.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.88939, 99.769th percentile) and third-party references are tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade Nagios XI to 5.8.6 or later, which the vendor changelog identifies as the fixed release.
- Restrict dashboard editing privileges to trusted administrators and review who holds admin accounts.
- Apply output encoding and input sanitization for dashboard fields if any custom code or plugins are in use.
- Deploy a content security policy that limits inline script execution in the Nagios XI interface.
Detection
- Review Nagios XI web logs for unusual requests to /dashboards/# and dashboard edit endpoints from unexpected sources.
- Monitor for anomalous admin session activity, such as unexpected configuration changes or new dashboard content.
- Search for known XSS payload patterns in dashboard names, descriptions, or saved dashboard content.
- Alert on outbound requests or script loads originating from administrator browser sessions on the Nagios XI host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://raxis.com/blog/cve-2021-38156 | ExploitThird Party Advisory |
| https://www.nagios.com/downloads/nagios-xi/change-log/ | Release NotesVendor Advisory |
| https://raxis.com/blog/cve-2021-38156 | ExploitThird Party Advisory |
| https://www.nagios.com/downloads/nagios-xi/change-log/ | Release NotesVendor Advisory |
Track CVE-2021-38156 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-38156), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.