CVE-2024-13994

CRITICAL

Nagios XI < 2024R1.1.2 - Missing Authorization via Insecure Login Option

Title source: llm
STIX 2.1

Description

Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option is enabled. Under this configuration, any user can create valid login credentials for other users without proper authorization. This can lead to unauthorized account creation, privilege escalation, or full compromise of the Nagios XI web interface depending on the target account.

References (3)

Core 3
Core References
Vendor Advisory vendor-advisory patch
https://www.nagios.com/products/security/#nagios-xi
Release Notes release-notes patch
https://www.nagios.com/changelog/nagios-xi/

Scores

CVSS v3 9.8
EPSS 0.0009
EPSS Percentile 25.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-862
Status published
Products (2)
nagios/nagios_xi 2024 r1 (5 CPE variants)
nagios/nagios_xi < 2024
Published Oct 30, 2025
Tracked Since Feb 18, 2026