{"id":"CVE-2025-44823","title":"Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/system/get_users call","summary":"Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/system/get_users call. This is GL:NLS#475.","severity":"critical","cvss":9.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-497"],"vendor":"nagios","product":"log_server","affected":["log_server < 2024","log_server = 2024"],"patched":["log_server 2024"],"published":"2025-10-07","updated":"2026-10-08","sourceUpdated":"2026-10-08T13:10:00.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-44823","references":[{"url":"https://www.exploit-db.com/exploits/52177","label":"cve@mitre.org"},{"url":"https://www.nagios.com/changelog/#log-server","label":"cve@mitre.org"},{"url":"https://www.exploit-db.com/exploits/52177","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","exploit-available"],"epss":0.16118,"epssPercentile":0.96848,"exploits":{"github":1,"githubRepos":["https://github.com/skraft9/CVE-2025-44823"],"checkedAt":"2026-10-08T13:43:30.321Z"},"exploitAvailable":true,"ingestedAt":"2026-10-08T13:42:54.980Z","slug":"CVE-2025-44823","body":"## Overview\n\nNagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/system/get_users call. This is GL:NLS#475.\n\n## Affected\n\n- `log_server < 2024`\n- `log_server = 2024`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `log_server 2024`","depth":"abyssal","depthScore":70,"depthScoreParts":{"impact":54.5,"likelihood":3.2,"exploitation":12,"ransomware":0},"changes":[]}