Back

HIGH

Nagios XI < 2011R1.9 Race Conditions in Crontab Install Scripts LPE

Published Oct 30, 2025

Description

Nagios XI versions prior to 2011R1.9 contain privilege escalation vulnerabilities in the scripts that install or update system crontab entries. Due to time-of-check/time-of-use race conditions and missing synchronization or final-path validation, a local low-privileged user could manipulate filesystem state during crontab installation to influence the files or commands executed with elevated privileges, resulting in execution with higher privileges.

Affected products

Remediation

Vendor solution

Nagios addresses this vulnerability as "Fixed security escalation race conditions in crontab install scripts."

Metrics

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Oct 30, 2025
Updated Nov 17, 2025
Reserved Oct 28, 2025
CISA Vulnrichment
Updated Oct 31, 2025
NVD
Status Analyzed
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a