CVE-2023-48082: Nagios XI

Critical severity, CVSS 9.1. EPSS: 1.5% chance of exploitation in the next 30 days.

Nagios XI before 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers to possibly generate the same set of API keys for all users and utilize them to authenticate.

Affected products

  • Nagios Nagios XI: before 2014 (fixed in 2014); version 2014 only

Published 2024-10-14. Last modified 2026-06-17.