CVE-2026-2043 is a command injection vulnerability in Nagios Host's esensors_websensor_configwizard_func method, affecting Nagios XI. This flaw allows authenticated remote attackers to execute arbitrary code on the affected Nagios Host installations. With a CVSS score of 8.8 (High), it presents a significant risk due to its low attack complexity and the potential for complete compromise of confidentiality, integrity, and availability. While authentication is required, successful exploitation grants attackers code execution in the context of the service account. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2026CPE matchmatch criteria | cpe:2.3:a:nagios:nagios_xi:2026:r1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Nagios XI Command Injection (CVE-2026-2043)
Mar 22, 2026Nagios XI Command Injection (CVE-2026-2043)
Mar 22, 2026Nagios XI Command Injection (CVE-2026-2043)
Mar 22, 2026Nagios XI Command Injection (CVE-2026-2043)
Mar 22, 2026