Nagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to a combination of sudo misconfiguration and group-writable application directories. The 'www-data' user is a member of the 'nagios' group, which has write access to '/usr/local/nagioslogserver/scripts', while several scripts in this directory are owned by root and may be executed via sudo without a password. A local attacker running as 'www-data' can move one of these root-owned scripts to a backup name and create a replacement script with attacker-controlled content at the original path, then invoke it with sudo. This allows arbitrary commands to be executed with root privileges, providing full compromise of the underlying operating system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides proof-of-concept exploits for two vulnerabilities in Nagios Log Server: CVE-2025-34322 (authenticated command injection) and CVE-2025-34323 (privilege escalation to root). The repository contains two main Python scripts: - CVE-2025-34322.py: Exploits an authenticated command injection vulnerability by injecting commands into the 'self_host_ip_address' parameter of the global settings. The output of the command is written to a web-accessible file, which is then retrieved. - root_exploit.py: Chains the command injection with a privilege escalation technique. It replaces a sudo-enabled script with a malicious payload that spawns a root reverse shell, then restores the original script. The exploit leverages the ability of the 'www-data' user to move and overwrite scripts in a writable directory and execute them as root via sudo. The README.md provides detailed manual exploitation steps and explains the underlying vulnerabilities. The exploits require valid credentials and network access to the Nagios Log Server web interface. The code is operational and demonstrates both arbitrary command execution and full root compromise on vulnerable systems.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.