VDB

CVE-2026-2042

CVE-2026-2042 PUBLISHED CVSS 7.199999809265137 HIGH

Nagios Host monitoringwizard Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this vulnerability. The specific flaw exists within the monitoringwizard module. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-28245.

EPSS 2.07% · 84.3th percentile

Risk Scores

CVSS 3.0
7.199999809265137
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
2.07%
84.3th percentile

Affected Products

VendorProductVersions
NagiosHost2026R1
nagiosnagios_xi2026

Exploit Intelligence

Timeline

  • Feb 12, 2026 PoC Published
  • Feb 12, 2026 CVE Published
  • Feb 21, 2026 EPSS Score
  • Feb 23, 2026 EPSS Score
  • Feb 24, 2026 EPSS Score
  • Feb 24, 2026 PoC Published
  • Feb 24, 2026 PoC Published
  • Feb 25, 2026 EPSS Score
  • Feb 26, 2026 EPSS Score
  • Feb 28, 2026 EPSS Score
  • Mar 1, 2026 EPSS Score
  • Mar 3, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›