{"id":"CVE-2025-34323","title":"Nagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to a combination of sudo misconfiguration and group-writable application directories","summary":"Nagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to a combination of sudo misconfiguration and group-writable application directories. The 'www-data' user is a member of the 'nagios' group, …","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-732"],"vendor":"nagios","product":"log_server","affected":["log_server < 2026","log_server = 2026"],"patched":["log_server 2026"],"published":"2025-11-17","updated":"2026-10-07","sourceUpdated":"2026-10-07T21:10:00.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-34323","references":[{"url":"https://theyhack.me/Rooting-Nagios-Log-Server/","label":"disclosure@vulncheck.com"},{"url":"https://www.nagios.com/changelog/nagios-log-server/nagios-log-server-2026r1-0-1/","label":"disclosure@vulncheck.com"},{"url":"https://www.nagios.com/products/security/#log-server","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/nagios-log-server-local-privilege-escalation-via-writable-scripts-and-sudo-rules","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"epss":0.00325,"epssPercentile":0.23476,"ingestedAt":"2026-10-07T21:54:15.062Z","slug":"CVE-2025-34323","body":"## Overview\n\nNagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to a combination of sudo misconfiguration and group-writable application directories. The 'www-data' user is a member of the 'nagios' group, which has write access to '/usr/local/nagioslogserver/scripts', while several scripts in this directory are owned by root and may be executed via sudo without a password. A local attacker running as 'www-data' can move one of these root-owned scripts to a backup name and create a replacement script with attacker-controlled content at the original path, then invoke it with sudo. This allows arbitrary commands to be executed with root privileges, providing full compromise of the underlying operating system.\n\n## Affected\n\n- `log_server < 2026`\n- `log_server = 2026`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `log_server 2026`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}