Vulnerabilities in Centreon

52 results
Vexday analysis

Com 51 CVEs catalogadas e nenhuma confirmada em exploração ativa no catálogo CISA KEV, o Centreon apresenta taxa de exploração abaixo da média geral do catálogo. Ainda assim, o cenário exige atenção: a CVE mais crítica em destaque, CVE-2022-41142, registra EPSS de 0,8614 — valor elevado que indica alta probabilidade de exploração —, e há 4 vulnerabilidades de severidade crítica no total. O tipo de falha mais frequente é CWE-89 (SQL Injection), categoria historicamente associada a impactos severos em integridade e confidencialidade de dados, reforçando a necessidade de revisão cuidadosa das superfícies de entrada da plataforma. A existência de ao menos uma PoC pública disponível reduz a barreira técnica para potenciais atacantes, tornando a priorização de patches críticos uma medida urgente para equipes que operam esse ambiente.

CVE-2024-23119HIGHCentreon insertGraphTemplate SQL Injection Remote Code Execution VulnerabilityEPSS 1.4%CVE-2023-51633HIGHCentreon sysName Cross-Site Scripting Remote Code Execution VulnerabilityEPSS 1.1%CVE-2026-14453CRITICALA user with low privileges can inject SSTI templates that can lead to RCE in open-ticketsEPSS 0.8%CVE-2026-2749CRITICALPath traversal in Centreon Open TicketsEPSS 0.5%CVE-2025-4646HIGHA high privilege user is able to create and use a valid admin API token in centreon-webEPSS 0.4%CVE-2025-4650HIGHUser with high privileges is able to introduce a SQLi using the Meta Service indicator pageEPSS 0.4%CVE-2025-8432HIGHCentreonBI user account on the MBI server can execute commands as root by modifying script runned by the CRONEPSS 0.4%CVE-2025-15026CRITICALUnauthenticated configuration import allows administrative account creation using AWIE componentEPSS 0.4%CVE-2025-3767HIGHSQL Injection in Centreon BAM boolean KPI listingEPSS 0.4%CVE-2025-3872HIGHPrivilege escalation by altering payload in contact formEPSS 0.4%CVE-2025-4649MEDIUMACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display all available logs.EPSS 0.4%CVE-2025-6791HIGHSecond order SQL injection available to user with low privilegeEPSS 0.3%CVE-2025-12514HIGHA user with elevated privileges is able to introduce a SQL Injection using the Open-tickets Notification rules configuration parametersEPSS 0.3%CVE-2026-2750CRITICALCommand Injection via CLAPI generatetrapsEPSS 0.3%CVE-2025-4647HIGHA user with elevated privileges can bypass sanitization measures by replacing the content of an existing SVGEPSS 0.3%CVE-2026-2751HIGHBlind SQL InjectionEPSS 0.3%CVE-2025-4648HIGHA user with elevated privileges can inject XSS by altering the content of a SVG media during the submit request.EPSS 0.3%CVE-2025-54892MEDIUMA user with elevated privileges can inject XSS in the SNMP traps group configuration pageEPSS 0.2%CVE-2025-54891MEDIUMA user with elevated privileges can inject XSS in the ACL Resource Access configuration pageEPSS 0.2%CVE-2025-54889MEDIUMA user with elevated privileges can inject XSS in the SNMP traps manufacturer configuration pageEPSS 0.2%