CVE-2023-53948: CAT03 Lilac-Reloaded

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

Lilac-Reloaded for Nagios 2.0.8 contains a remote code execution vulnerability in the autodiscovery feature that allows attackers to inject arbitrary commands. Attackers can exploit the lack of input filtering in the nmap_binary parameter to execute a reverse shell by sending a crafted POST request to the autodiscovery endpoint.

Affected products

  • CAT03 Lilac-Reloaded: up to and including 2.0.8

Published 2025-12-19. Last modified 2026-06-17.