CVE-2025-34298HIGH 8.8EPSS p43.4%
CVE-2025-34298CVE-2025-34298
Description
Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to an invalid value and, due to insufficient validation and authorization checks tied to email identity state, trigger inconsistent account state that granted elevated privileges or bypassed intended access controls.
Scoring
| CVSS 3.1 | 8.8 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.59% probability of exploitation · percentile 43.4% · 2026-06-18T12:00:27Z |
| Published | 2025-10-30 |
| Last modified | 2025-11-06 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Preservation of Permissionscwe-281 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.