What is CVE-2026-48550?
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a reflected cross-site scripting (XSS) vulnerability in `cmd.cgi` via the `NagFormId` parameter. An unauthenticated remote attacker can craft a malicious link that, when clicked by an authenticated user, executes arbitrary JavaScript in the victim's browser. Affected systems should be updated to the patched versions immediately.
Azərbaycanca: Nagios Core (4.5.14-dən əvvəl) və Nagios XI (2026R1.7-dən əvvəl) məhsullarında `cmd.cgi` faylında `NagFormId` parametri vasitəsilə reflected cross-site scripting (XSS) zəifliyi aşkarlanıb. Bu, autentifikasiya olunmamış uzaqdan hücumçuya xüsusi keçid hazırlayaraq autentifikasiyalı istifadəçinin brauzerində icazəsiz JavaScript kodunu icra etməyə imkan verir. Təhlükəsizlik üçün sistemləri göstərilən versiyalara yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Nagios
FAQ2
In which Nagios component does the CVE-2026-48550 vulnerability exist?
The vulnerability exists in the `cmd.cgi` file via the `NagFormId` parameter.
Does the attacker need to be authenticated to exploit this reflected XSS vulnerability?
No, the attacker can be an unauthenticated remote user, but the attack requires an authenticated user to click a malicious link.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.