Cross-site Request Forgery (CSRF) Affecting nagios4 package, versions *


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.17% (7th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN13-NAGIOS4-18860639
  • published16 Aug 2026
  • disclosed12 Aug 2026

Introduced: 12 Aug 2026

NewCVE-2026-48551  (opens in a new tab)
CWE-352  (opens in a new tab)

How to fix?

There is no fixed version for Debian:13 nagios4.

NVD Description

Note: Versions mentioned in the description apply only to the upstream nagios4 package and not the nagios4 package as distributed by Debian. See How to fix? for Debian:13 relevant fixed versions and status.

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply matching cookie and request parameter values to bypass CSRF protection, enabling unauthenticated attackers to run commands as authorized users via malicious links.

CVSS Base Scores

version 3.1