Nagios XI RCE: CCM Run Check Shell Injection (CVE-2025-34286)
CVE-2025-34286 Published on October 30, 2025

Nagios XI < 2026R1 RCE via Run Check Command in CCM
Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run Check command. Insufficient validation/escaping of parameters used to build backend command lines allows an authenticated administrator to inject shell metacharacters that are executed on the server. Successful exploitation results in arbitrary command execution with the privileges of the Nagios XI web application user and can be leveraged to gain control of the underlying host operating system.

Vendor Advisory NVD

Weakness Type

What is a Shell injection Vulnerability?

The software constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

CVE-2025-34286 has been classified to as a Shell injection vulnerability or weakness.


Products Associated with CVE-2025-34286

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2025-34286 are published in these products:

 
 

Affected Versions

Nagios XI:

Exploit Probability

EPSS
0.69%
Percentile
71.53%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.