CVE-2024-24402: Nagios XI

Critical severity, CVSS 9.8. EPSS: 3.4% chance of exploitation in the next 30 days.

An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.

Affected products

  • Nagios Nagios XI: version 2024 only

Published 2024-02-26. Last modified 2026-06-17.