CVE-2023-47403 is an authorization flaw in Nagios XI affecting the Missing Objects page. According to the provided context, the page and its associated functionality were accessible to all authenticated users, regardless of whether they held administrator privileges. This indicates missing authorization checks on functionality intended to be restricted to administrators. As a result, a low-privileged authenticated user could access the Missing Objects page and perform actions reserved for administrative users.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authorization bypass in Nagios XI that exposes the Missing Objects administrative page and its actions to any authenticated user.
A low-severity authorization vulnerability in Nagios XI that allows any authenticated user to access the Missing Objects page and perform administrative actions such as changing CCM settings, clearing records, and applying configuration.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.