EIP-2026-104350

PRE-CVE

Nagios XI Version 2024R1.01 - SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-104350. PoCs published by Jarod Jaslow (MAWK).

AI-analyzed exploit summary This exploit leverages SQL injection (SQLi) in Nagios XI to extract credentials, create an admin account, and execute a reverse shell. It uses sqlmap for automated SQLi exploitation and integrates with the Nagios XI API for privilege escalation.

Description

Nagios XI Version 2024R1.01 - SQL Injection

Exploits (1)

exploitdb WORKING POC
by Jarod Jaslow (MAWK) · pythonwebappsmultiple
https://www.exploit-db.com/exploits/51925

This exploit leverages SQL injection (SQLi) in Nagios XI to extract credentials, create an admin account, and execute a reverse shell. It uses sqlmap for automated SQLi exploitation and integrates with the Nagios XI API for privilege escalation.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Nagios XI Version 2024R1.01
Auth required
Prerequisites: Valid credentials for initial authentication · Network access to the target Nagios XI instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026