CVE-2025-34227 is an authenticated command injection vulnerability affecting Nagios XI versions prior to 2026R1. The flaw exists in multiple database-related configuration wizards, specifically the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. An authenticated user can inject shell metacharacters into arguments supplied to the service by these wizards, resulting in execution of arbitrary system commands on the underlying host. Based on the provided information, command execution occurs in the security context of the nagios user.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
nagios user. This can enable compromise of monitoring infrastructure, access to data and credentials available to the Nagios service account, modification of monitoring configuration, staging of additional tooling, and potential follow-on privilege escalation depending on host configuration and local privilege boundaries.If you can’t patch tonight, do this now.
nagios user. Where operationally feasible, harden the host and constrain the nagios account's OS-level permissions to reduce post-exploitation impact.Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept exploit for CVE-2025-34227, an authenticated command injection vulnerability in the Configuration Wizard of Nagios XI. The repository contains two files: a Python exploit script (CVE-2025-34227.py) and a README.md with usage instructions and a curl-based PoC. The Python script automates the exploitation process by logging into the Nagios XI web interface, retrieving necessary tokens, and submitting a malicious payload via the 'database' parameter to the /config/monitoringwizard.php endpoint. Successful exploitation allows an authenticated attacker to execute arbitrary system commands on the server. The exploit requires valid credentials and network access to the Nagios XI web interface. The code is a straightforward proof-of-concept and does not include advanced features such as payload customization or post-exploitation modules.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.