Privilege Escalation in Nagios XI <2024R1.2 via NagVis Config
CVE-2024-14004 Published on October 30, 2025

Nagios XI < 2024R1.2 Privilege Escalation via NagVis Configuration (nagvis.conf)
Nagios XI versions prior to 2024R1.2 contain a privilege escalation vulnerability related to NagVis configuration handling (nagvis.conf). An authenticated user could manipulate NagVis configuration data or leverage insufficiently validated configuration settings to obtain elevated privileges on the Nagios XI system.

Vendor Advisory NVD

Weakness Type

Improper Privilege Management

The software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.


Products Associated with CVE-2024-14004

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2024-14004 are published in these products:

 
 

Affected Versions

Nagios XI:

Exploit Probability

EPSS
0.08%
Percentile
22.66%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.