CVE-2020-28902: Nagios Fusion

Critical severity, CVSS 9.8. EPSS: 8.4% chance of exploitation in the next 30 days.

Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php.

Affected products

  • Nagios Fusion: up to and including 4.1.8

Published 2021-05-24. Last modified 2026-06-17.