---
id: CVE-2021-37345
title: >-
  Nagios XI before version 5.8.5 is vulnerable to local privilege escalation
  because xi-sys.cfg is being imported from the var directory for some scripts
  with elevated permissions.
summary: >-
  Nagios XI before version 5.8.5 is vulnerable to local privilege escalation
  because xi-sys.cfg is being imported from the var directory for some scripts
  with elevated permissions.
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-269
vendor: nagios
product: nagios_xi
affected:
  - nagios_xi < 5.8.5
patched:
  - nagios_xi 5.8.5
published: '2021-08-13'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-37345'
references:
  - url: 'https://www.nagios.com/downloads/nagios-xi/change-log/'
    label: cve@mitre.org
  - url: 'http://nagios.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.nagios.com/downloads/nagios-xi/change-log/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00571
epssPercentile: 0.45728
ingestedAt: '2026-07-06T17:03:23.564Z'
---

## Overview

Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scripts with elevated permissions.

## Affected

- `nagios_xi < 5.8.5`

## Remediation

Upgrade past the affected range:

- `nagios_xi 5.8.5`
