Nagios Core/ XI DOM-based XSS via jsonquery.js (<=4.5.14 & <=2026R1.7)
CVE-2026-48552 Published on August 12, 2026
Nagios Core / XI DOM-based XSS via jsonquery.js
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js. Unencoded JSON string values reflected from stored fields are inserted into the DOM without sanitization, allowing attackers to run arbitrary JavaScript in the victim's browser.
Vulnerability Analysis
CVE-2026-48552 is exploitable with network access. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
What is a XSS Vulnerability?
The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVE-2026-48552 has been classified to as a XSS vulnerability or weakness.
Products Associated with CVE-2026-48552
Want to know whenever a new CVE is published for Nagios Core? stack.watch will email you.
Affected Versions
Nagios Enterprises, LLC. Nagios Core:- Before 4.5.14 is affected.
- Before 2026R1.7 is affected.