CVE-2026-48548
MEDIUM
NVD
CVSS Score
6.5
Severity
MEDIUM
Published
Aug 26, 2026
Vendor
unknown
Description
Nagios Core before 4.5.12 contains a cross-site request forgery vulnerability in cmd.cgi where the CSRF protection mechanism passes validation when the NagFormId cookie is absent. Attackers can craft a malicious cross-site POST request to execute arbitrary Nagios commands as a currently authenticated user without their knowledge or consent.