CVE-2018-17148: Nagios XI

Critical severity, CVSS 9.8. EPSS: 3.7% chance of exploitation in the next 30 days.

An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios XI before 5.5.4 allows remote attackers to gain access to configuration files containing confidential credentials.

Affected products

  • Nagios Nagios XI: before 5.5.4 (fixed in 5.5.4)

Published 2019-06-19. Last modified 2026-06-17.