CVE-2018-8733: Nagios XI
Critical severity, CVSS 9.8. EPSS: 26.6% chance of exploitation in the next 30 days.
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to make configuration changes and leverage an authenticated SQL injection vulnerability.
Affected products
- Nagios Nagios XI: from 5.2.0, before 5.4.13 (fixed in 5.4.13)
Published 2018-04-18. Last modified 2026-06-17.