What is CVE-2026-48552?
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a DOM-based XSS vulnerability in jsonquery.js. Unsanitized JSON string values from stored fields are reflected into the DOM, allowing attackers to execute arbitrary JavaScript in the victim's browser. Upgrade to the patched versions immediately.
Azərbaycanca: Nagios Core (4.5.14-dən əvvəl) və Nagios XI (2026R1.7-dən əvvəl) jsonquery.js-də DOM-based XSS zəifliyi ilə üzləşib. Saxlanılan sahələrdən gələn təmizlənməmiş JSON məlumatları DOM-a birbaşa daxil edildiyindən, təcavüzkar istifadəçi brauzerində ixtiyari JavaScript icra edə bilər. Dərhal müvafiq versiyalara yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Nagios
FAQ2
What type of XSS vulnerability exists in Nagios Core and Nagios XI via JSON data?
A DOM-based XSS vulnerability exists in jsonquery.js. Unsanitized JSON string values from stored fields are reflected directly into the DOM, allowing attackers to execute arbitrary JavaScript in the victim's browser.
To which versions should I upgrade to fix CVE-2026-48552?
The vulnerability affects Nagios Core before 4.5.14 and Nagios XI before 2026R1.7. It is recommended to upgrade immediately to Nagios Core 4.5.14 or later, and Nagios XI 2026R1.7 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.