Vulnerability record · CVE-2026-2043 · published 20 February 2026
CVE-2026-2043: Nagios XI config wizard command injection RCE
Nagios · Nagios Xi
Nagios XI's esensors_websensor_configwizard_func method passes a user-supplied string into a system call without validation, allowing OS command injection. An authenticated attacker can run arbitrary commands as the service account, and the flaw is remotely reachable over the network.
Description
Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this vulnerability. The specific flaw exists within the esensors_websensor_configwizard_func method. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-28249.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote authenticated command injection with high confidentiality, integrity and availability impact and a very high EPSS score, though no KEV listing or confirmed in-the-wild exploitation is documented.
What it is
Nagios XI's esensors_websensor_configwizard_func method passes a user-supplied string into a system call without validation, allowing OS command injection. An authenticated attacker can run arbitrary commands as the service account, and the flaw is remotely reachable over the network.
Impact
An attacker with valid credentials gains arbitrary code execution in the context of the Nagios XI service account, compromising the monitoring host and potentially the systems it manages.
Attack surface
Reached over the network through the Nagios XI web interface (AV:N) with low privileges required (PR:L) and no user interaction (UI:N). Authentication is required, so the attacker must already hold a valid account.
Exploitation
Not listed in CISA KEV and no public exploit tag appears in the references, but EPSS is very high at 0.729 (99.4th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Apply the fixed release noted in the Nagios XI 2026R1.0.1 changelog.
- Restrict access to the Nagios XI web interface to trusted networks or administrative users.
- Audit and minimize accounts with access to configuration wizards; remove unused or low-privilege accounts.
- Monitor the Nagios XI service account for unexpected child processes or outbound connections.
Detection
- Alert on shell metacharacters or command separators in requests to the esensors websensor config wizard endpoint.
- Monitor for unexpected child processes spawned by the Nagios XI web/service account.
- Review web server and Nagios XI logs for anomalous requests to config wizard paths from authenticated sessions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.nagios.com/changelog/nagios-xi/nagios-xi-2026r1-0-1/ | ProductRelease Notes |
| https://www.zerodayinitiative.com/advisories/ZDI-26-072/ | Third Party Advisory |
Track CVE-2026-2043 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-2043), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.