CVE-2023-40933: Nagios XI

High severity, CVSS 8.8. EPSS: 3.5% chance of exploitation in the next 30 days.

A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function.

Affected products

  • Nagios Nagios XI: before 5.11.2 (fixed in 5.11.2)

Published 2023-09-19. Last modified 2026-07-09.