---
id: CVE-2025-34283
title: "Nagios XI versions prior to\_2024R1.4.2\_revealed API keys to users who were not authorized for API access when using Neptune themes"
summary: "Nagios XI versions prior to\_2024R1.4.2\_revealed API keys to users who were not authorized for API access when using Neptune themes. An authenticated user without API privileges could view another user's or their own API key value."
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-497
vendor: nagios
product: nagios_xi
affected:
  - nagios_xi < 2024
  - nagios_xi = 2024
patched:
  - nagios_xi 2024
published: '2025-10-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T18:17:57.633'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-34283'
references:
  - url: 'https://www.nagios.com/changelog/nagios-xi/'
    label: disclosure@vulncheck.com
  - url: 'https://www.nagios.com/products/security/#nagios-xi'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/nagios-xi-api-key-disclosure-via-neptune-themes
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.0104
epssPercentile: 0.62662
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2025-10-31T15:06:50.951117Z'
scores:
  nvd: 6.5
  cna: 7.1
ingestedAt: '2026-09-30T18:17:24.560Z'
---

## Overview

Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Neptune themes. An authenticated user without API privileges could view another user's or their own API key value.

## Affected

- `nagios_xi < 2024`
- `nagios_xi = 2024`

## Remediation

Upgrade past the affected range:

- `nagios_xi 2024`
