CVE-2019-9165: Nagios XI

Critical severity, CVSS 9.8. EPSS: 5.3% chance of exploitation in the next 30 days.

SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and malicious user id.

Affected products

  • Nagios Nagios XI: before 5.5.11 (fixed in 5.5.11)

Published 2019-03-28. Last modified 2026-06-17.