Nagios Core/ XI DOM-based XSS via jsonquery.js (<=4.5.14 & <=2026R1.7)
CVE-2026-48552 Published on August 12, 2026

Nagios Core / XI DOM-based XSS via jsonquery.js
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js. Unencoded JSON string values reflected from stored fields are inserted into the DOM without sanitization, allowing attackers to run arbitrary JavaScript in the victim's browser.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-48552 is exploitable with network access. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
PASSIVE

Weakness Type

What is a XSS Vulnerability?

The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

CVE-2026-48552 has been classified to as a XSS vulnerability or weakness.


Products Associated with CVE-2026-48552

Want to know whenever a new CVE is published for Nagios Core? stack.watch will email you.

 

Affected Versions

Nagios Enterprises, LLC. Nagios Core: Nagios Enterprises, LLC. Nagios XI: