CVE-2020-36856 Details
Description
Nagios XI versions prior to 5.6.14 contain an authenticated remote command execution vulnerability in the CCM command_test.php script. Insufficient validation of the `address` parameter allows an authenticated user with access to the Core Config Manager to inject shell metacharacters that are incorporated into backend command invocations. Successful exploitation enables arbitrary command execution with the privileges of the Nagios XI web application user and may be leveraged to execute commands on the underlying XI host, modify system configuration, or fully compromise the host.
A remote command execution vulnerability has been identified in Nagios XI versions prior to 5.6.14. This vulnerability exists in the Core Config Manager (CCM) command_test.php script, where inadequate validation of the 'address' parameter allows authenticated users to inject shell metacharacters. These injected characters are then executed as commands on the server, with the same privileges as the Nagios XI web application user. Exploitation of this vulnerability could lead to unauthorized command execution on the host running Nagios XI, potentially allowing an attacker to modify system configurations or compromise the entire system.
Users can upgrade to Nagios XI version 5.6.14 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 31, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.nagios.com/changelog/nagios-xi/ | [email protected] | Release Notes |
| https://www.nagios.com/products/security/#nagios-xi | [email protected] | Release Notes |
| https://www.vulncheck.com/advisories/nagios-xi-authenticated-rce-command-test-php-via-address | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nagios nagios xi | < 5.6.14 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 5, 2025 | Initial Analysis | [email protected] |
| Oct 30, 2025 | New CVE Received | [email protected] |