Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The getprofile.sh script, invoked by downloading a system profile (profile.php?cmd=download), is executed as root via a passwordless sudo entry; the script executes check_plugin, which is owned by the nagios user. A user logged into Nagios XI with permissions to modify plugins, or the nagios user on the server, can modify the check_plugin executable and insert malicious commands to execute as root.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 22 Oct 2025 00:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | 
Tue, 21 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | 
Tue, 21 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | 
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | epss 
 | epss 
 | 
Tue, 04 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | kev 
 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published: 2019-09-05T16:50:38.000Z
Updated: 2025-10-21T23:45:31.401Z
Reserved: 2019-09-05T00:00:00.000Z
Link: CVE-2019-15949
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-05T01:03:32.416Z
 NVD
                        NVD
                    Status : Modified
Published: 2019-09-05T17:15:12.327
Modified: 2025-10-22T00:16:35.887
Link: CVE-2019-15949
 Redhat
                        Redhat
                    No data.