CVE-2020-28911: Nagios Fusion

Medium severity, CVSS 6.5. EPSS: 3.6% chance of exploitation in the next 30 days.

Incorrect Access Control in Nagios Fusion 4.1.8 and earlier allows low-privileged authenticated users to extract passwords used to manage fused servers via the test_server command in ajaxhelper.php.

Affected products

  • Nagios Fusion: up to and including 4.1.8

Published 2021-05-24. Last modified 2026-06-17.