← Vulnerability feed

Vulnerability record · CVE-2024-24401 · published 26 February 2024

CVE-2024-24401: Nagios XI monitoringwizard.php SQL injection allows remote code execution

Nagios · Nagios Xi

Nagios XI 2024R1.01 contains a SQL injection flaw in the monitoringwizard.php component. A remote attacker can send a crafted payload that leads to arbitrary code execution on the affected server. Because the flaw is network reachable and needs no credentials, it is a serious risk to exposed Nagios XI installations.

9.8 CVSS 3.1 Critical EPSS 46% · top 1.2% CWE-89 · SQL injection
9.8CVSS 3.1 base score
46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or user interaction required and a high EPSS score make this a top remediation priority despite no KEV listing.

What it is

Nagios XI 2024R1.01 contains a SQL injection flaw in the monitoringwizard.php component. A remote attacker can send a crafted payload that leads to arbitrary code execution on the affected server. Because the flaw is network reachable and needs no credentials, it is a serious risk to exposed Nagios XI installations.

Impact

An attacker can execute arbitrary code on the Nagios XI host, gaining control of the monitoring server and potentially pivoting to systems it manages.

Attack surface

Reached over the network through the monitoringwizard.php component; the CVSS vector indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no public exploit references are provided, but EPSS is high at roughly 0.46 (98.7th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Upgrade Nagios XI to a version later than 2024R1.01 per the vendor changelog.
  • Restrict network access to the Nagios XI web interface to trusted management networks.
  • Enforce authentication and least privilege on the Nagios XI application and its database account.
  • Monitor the vendor changelog and advisories for the fixed release and apply it promptly.

Detection

  • Review web server and Nagios XI logs for suspicious requests to monitoringwizard.php, especially SQL metacharacters or encoded payloads.
  • Alert on unexpected child processes or command execution spawned by the Nagios XI web or database service.
  • Baseline and monitor database queries from the Nagios XI application for anomalous SQL patterns.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-24401 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-25296Nagios XI Windows WMI Config Wizard OS Command InjectionNagios XI 5.7.5 fails to sanitize authenticated user input in the windowswmi config wizard file, allowing OS command injection. Because the affected …KEVEPSS 72%analysed8.8CVE-2021-25297Nagios XI switch config wizard OS command injectionNagios XI 5.7.5 fails to sanitize authenticated user input in the switch configuration wizard file switch.inc.php, allowing OS command injection via …KEVEPSS 57%analysed8.8CVE-2021-25298Nagios XI cloud-vm config wizard OS command injectionNagios XI 5.7.5 fails to properly sanitize authenticated user input in /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php, all…KEVEPSS 75%analysed8.8CVE-2019-15949Nagios XI getprofile.sh command injection allows root code executionNagios XI before 5.6.6 runs the getprofile.sh script as root through a passwordless sudo entry when a system profile is downloaded. Because that scri…KEVEPSS 77%analysed9.8CVE-2024-24402Nagios xi improper privilege management vulnerabilityAn issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.EPSS 3.4%9.8CVE-2023-48085Nagios XI command_test.php remote code executionNagios XI before 5.11.3 contains a remote code execution flaw in the command_test.php component, classified as code injection (CWE-94). The CVSS 3.1 …EPSS 76%analysed9.8CVE-2023-48084Nagios xi sql injection vulnerabilityNagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.EPSS 34%9.8CVE-2022-38250Nagios xi sql injection vulnerabilityNagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page.EPSS 3.0%

Source: NIST National Vulnerability Database (record CVE-2024-24401), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.