---
id: CVE-2024-13986
title: >-
  Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by
  chaining two flaws: an arbitrary file upload and a path traversal in the Core
  Config Snapshots interface
summary: >-
  Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by
  chaining two flaws: an arbitrary file upload and a path traversal in the Core
  Config Snapshots interface. The issue arises from insufficient validation of
  file path…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
  - CWE-434
  - CWE-22
  - CWE-434
vendor: nagios
product: nagios_xi
affected:
  - nagios_xi < 2024
  - nagios_xi = 2024
patched:
  - nagios_xi 2024
published: '2025-08-28'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T21:10:00.130'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-13986'
references:
  - url: 'https://theyhack.me/Nagios-XI-Authenticated-RCE'
    label: disclosure@vulncheck.com
  - url: 'https://www.nagios.com/changelog/nagios-xi/'
    label: disclosure@vulncheck.com
  - url: 'https://www.nagios.com/products/security/#nagios-xi'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/nagios-xi-authenticated-arbitrary-file-upload-path-traversal-rce
    label: disclosure@vulncheck.com
  - url: 'https://theyhack.me/Nagios-XI-Authenticated-RCE/'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.01736
epssPercentile: 0.7674
ingestedAt: '2026-09-26T21:38:01.484Z'
---

## Overview

Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload and a path traversal in the Core Config Snapshots interface. The issue arises from insufficient validation of file paths and extensions during MIB upload and snapshot rename operations. Exploitation results in the placement of attacker-controlled PHP files in a web-accessible directory, executed as the www-data user.

## Affected

- `nagios_xi < 2024`
- `nagios_xi = 2024`

## Remediation

Upgrade past the affected range:

- `nagios_xi 2024`
