Vulnerability record · CVE-2021-40344 · published 26 October 2021
CVE-2021-40344: Nagios XI admin panel unrestricted file upload leads to RCE
Nagios · Nagios Xi
Nagios XI 5.8.5 allows an administrator to upload files with arbitrary extensions in the Custom Includes section of the Admin panel, as long as the MIME type is an image. A crafted PHP script can therefore be uploaded and executed, giving remote command execution.
Description
An issue was discovered in Nagios XI 5.8.5. In the Custom Includes section of the Admin panel, an administrator can upload files with arbitrary extensions as long as the MIME type corresponds to an image. Therefore it is possible to upload a crafted PHP script to achieve remote command execution.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote command execution with high EPSS and public exploit detail, though it requires an authenticated administrator account.
What it is
Nagios XI 5.8.5 allows an administrator to upload files with arbitrary extensions in the Custom Includes section of the Admin panel, as long as the MIME type is an image. A crafted PHP script can therefore be uploaded and executed, giving remote command execution.
Impact
An attacker with admin access gains remote command execution on the Nagios XI host, allowing full compromise of the monitoring server and any credentials or data it holds.
Attack surface
Reached over the network through the Nagios XI Admin panel Custom Includes upload feature. The CVSS vector requires high privileges (PR:H) and no user interaction (UI:N), so a valid administrator account is needed.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.66, 99th percentile) and a third-party advisory is tagged Exploit, indicating public exploit detail exists. No ransomware usage is documented.
What to do
- Upgrade Nagios XI past 5.8.5 per the vendor release notes.
- Restrict admin panel access to trusted networks and limit the number of administrator accounts.
- Enforce server-side validation of uploaded file extensions and content, not just MIME type.
- Store uploaded includes outside the web root or disable PHP execution in upload directories.
- Monitor and audit Custom Includes uploads for unexpected PHP files.
Detection
- Alert on new or modified files in Nagios XI Custom Includes and web-accessible upload directories.
- Detect PHP files written to upload paths and any subsequent web requests to those files.
- Monitor web server logs for POST requests to the Admin Custom Includes upload endpoint followed by execution of uploaded scripts.
- Watch for unexpected child processes spawned by the Nagios XI web server user.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXT | Release NotesVendor Advisory |
| https://synacktiv.com | Not Applicable |
| https://www.synacktiv.com/sites/default/files/2021-10/Nagios_XI_multiple_vulnerabilities_0.pdf | ExploitThird Party Advisory |
| https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXT | Release NotesVendor Advisory |
| https://synacktiv.com | Not Applicable |
| https://www.synacktiv.com/sites/default/files/2021-10/Nagios_XI_multiple_vulnerabilities_0.pdf | ExploitThird Party Advisory |
Track CVE-2021-40344 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-40344), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.