CVE-2026-5131 Details
Description
GREENmod uses named pipes for communication between plugins, the web portal, and the system service, but the access control lists for these pipes are configured incorrectly. This allows an attacker to communicate with the stream and upload any XML or JSON file, which will be processed by the named pipe with the privileges of the user under whose context the service is running. This allows for Server-Side Request Forgery to any Windows system on which the agent is installed and which provides communication via SMB or WebDav. This issue was fixed in version 2.8.33.
A Server-Side Request Forgery (SSRF) vulnerability has been identified in Nomios GREENmod versions prior to 2.8.33. The issue arises from incorrectly configured access control lists for named pipes used for communication between plugins, the web portal, and the system service. This misconfiguration allows an attacker to interact with the named pipe stream and upload arbitrary XML or JSON files. The uploaded files are processed by the named pipe with the privileges of the user under whose context the service is running. This vulnerability enables SSRF attacks to any Windows system that has the GREENmod agent installed and allows communication via SMB or WebDAV.
Users can upgrade to GREENmod version 2.8.33 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/posts/2026/04/CVE-2026-5131 | [email protected] | |
| https://www.nomios.pl/greenmod/ | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 17, 2026 | New CVE Received | [email protected] |