CVE-2020-28906: Nagios Fusion

High severity, CVSS 8.8. EPSS: 6.2% chance of exploitation in the next 30 days.

Incorrect File Permissions in Nagios XI 5.7.5 and earlier and Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root. Low-privileged users are able to modify files that are included (aka sourced) by scripts executed by root.

Affected products

  • Nagios Fusion: up to and including 4.1.8
  • Nagios Nagios XI: up to and including 5.7.5

Published 2021-05-24. Last modified 2026-06-17.