CVE-2023-40934: Nagios XI

High severity, CVSS 7.2. EPSS: 2.4% chance of exploitation in the next 30 days.

A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings.

Affected products

  • Nagios Nagios XI: before 5.11.2 (fixed in 5.11.2)

Published 2023-09-19. Last modified 2026-07-09.