CVE-2020-15901: Nagios XI

High severity, CVSS 8.8. EPSS: 21.9% chance of exploitation in the next 30 days.

In Nagios XI before 5.7.3, ajaxhelper.php allows remote authenticated attackers to execute arbitrary commands via cmdsubsys.

Affected products

  • Nagios Nagios XI: before 5.7.2 (fixed in 5.7.2)

Published 2020-07-22. Last modified 2026-06-17.