Centreon Infra Monitoring OS Command Injection Vulnerability

Vulnerability

A high-privilege user can exploit a command injection vulnerability in the backup configuration of Centreon Infra Monitoring. This issue is present in versions 25.10.0 prior to 25.10.2, 24.10.0 prior to 24.10.15, and 24.04.0 prior to 24.04.19.

Impact

Exploitation of this vulnerability allows for arbitrary operating system commands to be executed, potentially leading to unauthorized actions or access on the server where Centreon is running.

Remediation

Users can upgrade to Centreon versions 25.10.2, 24.10.15, or 24.04.19 to address this vulnerability.

Added: Jan 5, 2026, 10:38 AM
Updated: Jan 5, 2026, 10:38 AM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
10.0
exploitability
4.8
remediation
7.7
relevance
1.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.