---
id: CVE-2024-14004
title: "Nagios XI versions prior to 2024R1.2 contain\_a privilege escalation vulnerability related to NagVis configuration handling (nagvis.conf)"
summary: "Nagios XI versions prior to 2024R1.2 contain\_a privilege escalation vulnerability related to NagVis configuration handling (nagvis.conf). An authenticated user could manipulate NagVis configuration data or leverage insufficiently validat…"
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-269
vendor: nagios
product: nagios_xi
affected:
  - nagios_xi < 2024
  - nagios_xi = 2024
patched:
  - nagios_xi 2024
published: '2025-10-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T18:17:56.167'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-14004'
references:
  - url: 'https://www.nagios.com/changelog/nagios-xi/'
    label: disclosure@vulncheck.com
  - url: 'https://www.nagios.com/products/security/#nagios-xi'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/nagios-xi-privilege-escalation-via-nagvis-configuration
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.01109
epssPercentile: 0.64629
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2025-10-31T13:05:57.004075Z'
scores:
  nvd: 8.8
  cna: 8.7
ingestedAt: '2026-09-30T18:17:24.566Z'
---

## Overview

Nagios XI versions prior to 2024R1.2 contain a privilege escalation vulnerability related to NagVis configuration handling (nagvis.conf). An authenticated user could manipulate NagVis configuration data or leverage insufficiently validated configuration settings to obtain elevated privileges on the Nagios XI system.

## Affected

- `nagios_xi < 2024`
- `nagios_xi = 2024`

## Remediation

Upgrade past the affected range:

- `nagios_xi 2024`
