CVE-2025-67255: Nagios XI

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

In NagiosXI 2026R1.0.1 build 1762361101, Dashboard parameters lack proper filtering, allowing any authenticated user to exploit a SQL Injection vulnerability.

Affected products

  • Nagios Nagios XI: version 2026 only

Published 2025-12-29. Last modified 2026-06-17.