---
id: CVE-2025-34287
title: >-
  Nagios XI versions prior to 2024R2 contain an improperly owned script,
  process_perfdata.pl, which is executed periodically as the nagios user but
  owned by www-data
summary: >-
  Nagios XI versions prior to 2024R2 contain an improperly owned script,
  process_perfdata.pl, which is executed periodically as the nagios user but
  owned by www-data. Because the file was writable by www-data, an attacker with
  web server p…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-732
vendor: nagios
product: nagios_xi
affected:
  - nagios_xi < 2024
  - nagios_xi = 2024
patched:
  - nagios_xi 2024
published: '2025-10-30'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-34287'
references:
  - url: 'https://www.nagios.com/changelog/nagios-xi/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/nagios-xi-privilege-escalation-via-improperly-owned-script
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00289
epssPercentile: 0.19676
ingestedAt: '2026-10-07T21:54:14.907Z'
---

## Overview

Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodically as the nagios user but owned by www-data. Because the file was writable by www-data, an attacker with web server privileges could modify its contents, leading to arbitrary code execution as the nagios user when the script is next run. This improper ownership and permission configuration enables local privilege escalation.

## Affected

- `nagios_xi < 2024`
- `nagios_xi = 2024`

## Remediation

Upgrade past the affected range:

- `nagios_xi 2024`
