Nagios Fusion versions prior to R2.1 contain a...
High severity
Unreviewed
Published
Oct 31, 2025
to the GitHub Advisory Database
•
Updated Oct 31, 2025
Description
Published by the National Vulnerability Database
Oct 30, 2025
Published to the GitHub Advisory Database
Oct 31, 2025
Last updated
Oct 31, 2025
Nagios Fusion versions prior to R2.1 contain a vulnerability due to the application not requiring re-authentication or session rotation when a user has enabled two-factor authentication (2FA). As a result, an adversary who has obtained a valid session could continue using the active session after the target user enabled 2FA, potentially preventing the legitimate user from locking the attacker out and enabling persistent account takeover.
References