CVE-2025-34273
MEDIUMDescription
Nagios Log Server versions prior to 2024R2.0.3 contain an incorrect authorization vulnerability that allows non-administrator users to delete global dashboards. The application did not correctly enforce authorization checks for the global dashboard deletion workflow, enabling lower-privileged users to remove dashboards that affect other users or the overall monitoring UI.
Is your site exposed to CVE-2025-34273?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| nagios | log_server |
| nagios | log_server |
| nagios | log_server |
| nagios | log_server |
| nagios | log_server |
| nagios | log_server |
| nagios | log_server |
| nagios | log_server |
| nagios | log_server |
| nagios | log_server |
| nagios | log_server |
| nagios | log_server |
| nagios | log_server |
| nagios | log_server |
| nagios | log_server |
References
Frequently Asked Questions
What is CVE-2025-34273? +
How severe is CVE-2025-34273? +
What products are affected by CVE-2025-34273? +
How do I check if I'm vulnerable to CVE-2025-34273? +
Related Vulnerabilities
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version …
Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.23.0 to …
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.access/list` permissions are not consistently …
An incorrect authorization vulnerability in MISP allows an organization administrator to target site administrator accounts belonging to the same organization …
Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. From version 2.1.1 …
Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server versions <= 26.4.0 exposes the …