CVE-2020-36868

Nagios XI versions prior to 5.7.3 contain a privilege escalation vulnerability in the getprofile.sh helper script. The script performed profile retrieval and initialization routines using insecure file/command handling and insufficient validation of attacker-controlled inputs, and in some deployments executed with elevated privileges. A local attacker with low-level access could exploit these weaknesses to cause the script to execute arbitrary commands or modify privileged files, resulting in privilege escalation.
CVSS

No CVSS.

Configurations

No configuration.

History

30 Oct 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-30 22:15

Updated : 2025-10-30 22:15


NVD link : CVE-2020-36868

Mitre link : CVE-2020-36868

CVE.ORG link : CVE-2020-36868


JSON object : View

Products Affected

No product.

CWE
CWE-73

External Control of File Name or Path

CWE-250

Execution with Unnecessary Privileges