CVE-2016-9566: Nagios

High severity, CVSS 7.8. EPSS: 4.9% chance of exploitation in the next 30 days.

base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.

Affected products

  • Nagios Nagios: up to and including 4.2.3

Published 2016-12-15. Last modified 2026-06-17.