High severity8.5NVD Advisory· Published Oct 7, 2025· Updated Jun 17, 2026
CVE-2025-44824
CVE-2025-44824
Description
Nagios Log Server before 2024R1.3.2 allows authenticated users (with read-only API access) to stop the Elasticsearch service via a /nagioslogserver/index.php/api/system/stop?subsystem=elasticsearch call. The service stops even though "message": "Could not stop elasticsearch" is in the API response. This is GL:NLS#474.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10<2024R1.3.2+ 9 more
- (no CPE)range: <2024R1.3.2
- (no CPE)range: 0
- cpe:2.3:a:nagios:log_server:*:*:*:*:*:*:*:*range: <2024
- cpe:2.3:a:nagios:log_server:2024:r1:*:*:*:*:*:*
- cpe:2.3:a:nagios:log_server:2024:r1.0.1:*:*:*:*:*:*
- cpe:2.3:a:nagios:log_server:2024:r1.0.2:*:*:*:*:*:*
- cpe:2.3:a:nagios:log_server:2024:r1.1:*:*:*:*:*:*
- cpe:2.3:a:nagios:log_server:2024:r1.2:*:*:*:*:*:*
- cpe:2.3:a:nagios:log_server:2024:r1.3:*:*:*:*:*:*
- cpe:2.3:a:nagios:log_server:2024:r1.3.1:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- www.nagios.com/changelog/nvdRelease Notes
News mentions
0No linked articles in our index yet.