Database/Control plane, storage & DevOps
Nagios XI: Docker Wizard command injection gives admins code execution as the web user
Impact
Input to the Docker Wizard is passed into backend command invocations without filtering shell metacharacters, so an authenticated administrator turns a configuration form into arbitrary commands running as the Nagios XI web user. A monitoring server is a high-value pivot: it holds check credentials, SSH keys and SNMP communities for much of the fleet, and it is reachable from everything it monitors. The privilege bar is the mitigating factor - this is an admin-to-shell escalation, not an unauthenticated break-in - so the realistic threat models are a stolen or shared admin session and an operator account that should not have had host-level reach.
Who can reach it
An authenticated Nagios XI administrator using the Docker Wizard in the web UI. Admin privileges are required; no exploitation is possible from an unauthenticated position.
What to do
Upgrade Nagios XI to 2024R1.2 or later, per the vendor changelog. This is a web application upgrade on the monitoring host - the Nagios services restart and checks gap briefly; no fleet nodes are touched. Where an upgrade has to wait, treat Nagios XI admin as equivalent to shell on the monitoring host: trim the admin list, put the UI behind SSO, and rotate the credentials the monitoring server stores for the fleet if any admin account is in doubt.
References
Related entries
- GitLab: an unauthenticated GraphQL directive can modify or delete public projects and user dataCVE-2026-19478 · GitLab CE/EE (GraphQL API directive handling)Critical
- CloudNativePG: a database owner escalates to PostgreSQL superuser and OS command execution in the podCVE-2026-55769 · CloudNativePG instance manager (unpinned search_path on superuser connections)Critical
- CloudNativePG instance manager (PostgreSQL connection search_path): The owner of any managed database — a roleNCVD-2026-048-cloudnativepg-instance-manager-p · CloudNativePG instance manager (PostgreSQL connection search_path)Critical
- Pure Storage FlashBlade management interface authentication: An attacker authenticates to the FlashBlade managementCVE-2023-4976 · Pure Storage FlashBlade management interface authenticationCritical
- MinIO (admin IAM import API): The IAM import API can be driven to grant an attacker administrative policy, converting aCVE-2024-55949 · MinIO (admin IAM import API)Critical
- Renovate: shell metacharacters in helmv3 registryAliases give commit-access users command executionCVE-2024-58376 · Renovate (helmv3 manager, registryAliases handling)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.