HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-48551 — Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site req...

·Source: NIST NVD

Updated:

Executive Summary

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply matching cookie and request parameter values to bypass CSRF protection, enabling unauthenticated attackers to run commands as authorized users via malicious links.

Analysis

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply matching cookie and request parameter values to bypass CSRF protection, enabling unauthenticated attackers to run commands as authorized users via malicious links. CVSS Score: 7.4. Published: 2026-08-12T17:17:27.353.

Indicators of Compromise (1)

CVE (1)
CVE-2026-48551
Source Attribution

Originally published by NIST NVD on Aug 12, 2026. Verified by: NIST.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-74790 — Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering...

Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusing a TemplateContext after tightening its MemberFilter, bypassing sandbox policies across requests or tenants.

CVE-2026-74790
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-73061 — Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedOb...

Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init-only setters, and perform mass assignment on public-setter properties, permanently altering live host objects after template rendering.

CVE-2026-73061
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-73056 — SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive...

SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) or a ?token= query parameter, and neither path is protected by the application's CAPTCHA/lockout mechanism (NeedCaptcha/WrongAuthCount). As a result, an

CVE-2026-73056
NIST NVD