---
id: CVE-2025-34277
title: "Nagios Log Server versions prior to\_2024R1.3.1 contain a code injection vulnerability where\_malformed dashboard ID values are not properly validated before being forwarded to an internal API.\_An attacker able to supply crafted dashboard …"
summary: "Nagios Log Server versions prior to\_2024R1.3.1 contain a code injection vulnerability where\_malformed dashboard ID values are not properly validated before being forwarded to an internal API.\_An attacker able to supply crafted dashboard …"
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
vendor: nagios
product: log_server
affected:
  - log_server < 2024
  - log_server = 2024
patched:
  - log_server 2024
published: '2025-10-30'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-34277'
references:
  - url: 'https://www.nagios.com/changelog/#log-server-2024R1'
    label: disclosure@vulncheck.com
  - url: 'https://www.nagios.com/products/security/#log-server'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/nagios-log-server-rce-via-malformed-dashboard-id
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.02154
epssPercentile: 0.81595
ingestedAt: '2026-10-07T21:54:14.905Z'
---

## Overview

Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID values are not properly validated before being forwarded to an internal API. An attacker able to supply crafted dashboard ID values can cause the system to execute attacker-controlled data, leading to arbitrary code execution in the context of the Log Server process.

## Affected

- `log_server < 2024`
- `log_server = 2024`

## Remediation

Upgrade past the affected range:

- `log_server 2024`
