What is CVE-2026-48554?
CVE-2026-48554 is an authenticated remote code execution (RCE) vulnerability affecting Nagios Core before 4.5.14 and Nagios XI before 2026R1.7. The flaw stems from unfiltered NOTIFICATION-family macro substitution (`$NOTIFICATIONCOMMENT$`, `$NOTIFICATIONAUTHOR$`) via the com_data parameter in a shell-reachable context. Affected users should immediately upgrade to the patched versions.
Azərbaycanca: CVE-2026-48554, Nagios Core (4.5.14-dən əvvəl) və Nagios XI (2026R1.7-dən əvvəl) məhsullarında autentifikasiya olunmuş uzaqdan kod icrası (RCE) zəifliyidir. Bu boşluq com_data parametri vasitəsilə NOTIFICATION ailə makrolarının (`$NOTIFICATIONCOMMENT$`, `$NOTIFICATIONAUTHOR$`) shell kontekstində filtrasiya olunmadan işlənməsi səbəbindən yaranır. Təsirə məruz qalan sistemlərdə administratorlar dərhal müvafiq versiyalara (4.5.14 və 2026R1.7) yeniləmə aparmalıdır.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Is authentication required to exploit CVE-2026-48554?
Yes, CVE-2026-48554 is an authenticated remote code execution (RCE) vulnerability.
Which versions should be upgraded to in order to mitigate CVE-2026-48554?
You should upgrade to Nagios Core 4.5.14 and Nagios XI 2026R1.7.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.