CVE-2025-44823

CRITICAL

Nagios Log Server <2024R1.3.2 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2025-44823. PoCs published by Seth Kraft, skraft9.

AI-analyzed exploit summary This exploit demonstrates an API-level vulnerability in Nagios Log Server 2024R1.3.1 that allows any user with a valid API token to retrieve a full list of user accounts along with their plaintext API keys, including administrator credentials. The PoC uses a simple curl command to exploit the vulnerable endpoint and retrieve sensitive information.

Description

Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/system/get_users call. This is GL:NLS#475.

Exploits (2)

exploitdb WORKING POC
by Seth Kraft · webappsmultiple
https://www.exploit-db.com/exploits/52177

This exploit demonstrates an API-level vulnerability in Nagios Log Server 2024R1.3.1 that allows any user with a valid API token to retrieve a full list of user accounts along with their plaintext API keys, including administrator credentials. The PoC uses a simple curl command to exploit the vulnerable endpoint and retrieve sensitive information.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Nagios Log Server 2024R1.3.1 and below
Auth required
Prerequisites: Valid API token
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by skraft9 · poc
https://github.com/skraft9/CVE-2025-44823

This PoC demonstrates an authenticated API key exposure vulnerability in Nagios Log Server 2024R1.3.1, allowing users with a valid API token to retrieve plaintext API keys of all users, including administrators. The exploit involves a simple GET request to a vulnerable endpoint, leading to privilege escalation and full system compromise.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Nagios Log Server 2024R1.3.1 and below
Auth required
Prerequisites: Valid API token for the target Nagios Log Server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 9.9
EPSS 0.1557
EPSS Percentile 96.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-497
Status published
Products (2)
nagios/log_server 2024 r1 (7 CPE variants)
nagios/log_server < 2024
Published Oct 07, 2025
Tracked Since Feb 18, 2026