Description
Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain root privileges on the underlying XI host. By abusing the migration workflow, an admin-level attacker could execute actions outside the intended security scope of the application, resulting in full control of the operating system.
Problem types
CWE-269 Improper Privilege Management
Product status
Any version before 2024R1.1.3
References
www.nagios.com/products/security/
www.nagios.com/changelog/nagios-xi/
www.vulncheck.com/...-migrate-server-feature-to-root-on-host