← Vulnerability feed

Vulnerability record · CVE-2026-2041 · published 20 February 2026

CVE-2026-2041: Nagios XI Zabbix agent config wizard command injection RCE

Nagios · Nagios Xi

Nagios XI's zabbixagent_configwizard_func method fails to validate a user-supplied string before passing it to a system call, allowing OS command injection. An authenticated attacker can run arbitrary commands as the service account, and the flaw is remotely reachable over the network.

8.8 CVSS 3.1 High EPSS 74% · top 0.5% CWE-78 · OS command injection
8.8CVSS 3.1 base score
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this vulnerability. The specific flaw exists within the zabbixagent_configwizard_func method. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-28250.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityRemote authenticated command injection with high confidentiality, integrity and availability impact and a very high EPSS score, though exploitation requires valid credentials.

What it is

Nagios XI's zabbixagent_configwizard_func method fails to validate a user-supplied string before passing it to a system call, allowing OS command injection. An authenticated attacker can run arbitrary commands as the service account, and the flaw is remotely reachable over the network.

Impact

An attacker with valid credentials gains arbitrary code execution in the context of the Nagios XI service account, enabling full compromise of the host and any data or credentials that account can reach.

Attack surface

Reachable over the network via the Nagios XI web interface (AV:N) with low privileges required (PR:L) and no user interaction (UI:N). The attacker must already hold an authenticated session.

Exploitation

Not listed in CISA KEV and no public exploit reference is provided, but EPSS is very high at 0.734 (99.4th percentile), indicating elevated near-term exploitation likelihood.

What to do

  • Apply the vendor fix from the Nagios XI 2026R1.0.1 release notes as soon as possible.
  • Restrict access to the Nagios XI web interface to trusted networks or administrative IPs.
  • Audit and minimize accounts with access to configuration wizards; enforce least privilege and strong authentication.
  • Monitor the Nagios XI service account for unexpected child processes or outbound connections.
  • Review logs for abnormal use of the Zabbix agent configuration wizard endpoint.

Detection

  • Alert on child processes spawned by the Nagios XI web/service process, especially shells or command interpreters.
  • Monitor for command metacharacters or shell syntax in requests to the Zabbix agent config wizard endpoint.
  • Baseline and alert on unusual outbound network connections originating from the Nagios XI host.
  • Review Nagios XI audit logs for configuration wizard actions by unexpected or low-privilege accounts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-2041 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-25296Nagios XI Windows WMI Config Wizard OS Command InjectionNagios XI 5.7.5 fails to sanitize authenticated user input in the windowswmi config wizard file, allowing OS command injection. Because the affected …KEVEPSS 72%analysed8.8CVE-2021-25297Nagios XI switch config wizard OS command injectionNagios XI 5.7.5 fails to sanitize authenticated user input in the switch configuration wizard file switch.inc.php, allowing OS command injection via …KEVEPSS 57%analysed8.8CVE-2021-25298Nagios XI cloud-vm config wizard OS command injectionNagios XI 5.7.5 fails to properly sanitize authenticated user input in /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php, all…KEVEPSS 75%analysed8.8CVE-2019-15949Nagios XI getprofile.sh command injection allows root code executionNagios XI before 5.6.6 runs the getprofile.sh script as root through a passwordless sudo entry when a system profile is downloaded. Because that scri…KEVEPSS 77%analysed9.8CVE-2024-24401Nagios XI monitoringwizard.php SQL injection allows remote code executionNagios XI 2024R1.01 contains a SQL injection flaw in the monitoringwizard.php component. A remote attacker can send a crafted payload that leads to a…EPSS 46%analysed9.8CVE-2024-24402Nagios xi improper privilege management vulnerabilityAn issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.EPSS 3.4%9.8CVE-2023-48085Nagios XI command_test.php remote code executionNagios XI before 5.11.3 contains a remote code execution flaw in the command_test.php component, classified as code injection (CWE-94). The CVSS 3.1 …EPSS 76%analysed9.8CVE-2023-48084Nagios xi sql injection vulnerabilityNagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.EPSS 34%

Source: NIST National Vulnerability Database (record CVE-2026-2041), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.