Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-104350. PoCs published by Jarod Jaslow (MAWK).
AI-analyzed exploit summary This exploit leverages SQL injection (SQLi) in Nagios XI to extract credentials, create an admin account, and execute a reverse shell. It uses sqlmap for automated SQLi exploitation and integrates with the Nagios XI API for privilege escalation.
Description
Nagios XI Version 2024R1.01 - SQL Injection
Exploits (1)
exploitdb
WORKING POC
by Jarod Jaslow (MAWK) · pythonwebappsmultiple
https://www.exploit-db.com/exploits/51925
This exploit leverages SQL injection (SQLi) in Nagios XI to extract credentials, create an admin account, and execute a reverse shell. It uses sqlmap for automated SQLi exploitation and integrates with the Nagios XI API for privilege escalation.
Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target:
Nagios XI Version 2024R1.01
Auth required
Prerequisites:
Valid credentials for initial authentication · Network access to the target Nagios XI instance
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026