What is CVE-2026-48551?
CVE-2026-48551 is a CSRF protection bypass in Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 via a self-supplied double-submit cookie. An attacker can match cookie and request parameter values to execute commands without authentication. Upgrade to the patched versions immediately.
Azərbaycanca: CVE-2026-48551 Nagios Core (4.5.13-dən əvvəl) və Nagios XI (2026R1.7-dən əvvəl) sistemlərində CSRF müdafiəsindən yan keçməyə imkan verən boşluqdur. Təcavüzkar self-supplied double-submit cookie üsulu ilə müdafiəni keçərək autentifikasiyasız əmrlər icra edə bilər. Sistemləri göstərilən versiyalara yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
Which versions of Nagios are affected by CVE-2026-48551?
This vulnerability affects Nagios Core versions before 4.5.13 and Nagios XI versions before 2026R1.7.
How can an attacker bypass the CSRF protection in CVE-2026-48551?
An attacker can bypass the CSRF protection by using a self-supplied double-submit cookie technique, matching cookie and request parameter values to execute commands without authentication.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.