Centreon Open Tickets Module Server-Side Template Injection Vulnerability Leading to Remote Code Execution

Vulnerability

A critical Server-Side Template Injection (SSTI) vulnerability has been identified in the Centreon open tickets module. This vulnerability allows for Remote Code Execution (RCE) because the message_confirm field is stored without proper sanitization. The unsanitized input is rendered through Smarty without any security policy, enabling authenticated users to inject and execute arbitrary code on the server. The exploitation of this vulnerability could lead to the disclosure of environment secrets and impact the availability of the Centreon Infra Monitoring product.

Impact

Exploitation of this vulnerability allows authenticated users to execute arbitrary code on the server, potentially leading to unauthorized access, modification of data, and disruption of services. Additionally, it could result in the disclosure of sensitive environment secrets.

Remediation

Users can upgrade to Centreon Open Tickets versions 26.05.1, 25.10.9, 24.10.14, or Centreon Web versions 25.10.15 and 24.10.28 to address this vulnerability.

Added: Jul 13, 2026, 9:30 AM
Updated: Jul 13, 2026, 9:30 AM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
7.5
exploitability
4.7
remediation
7.0
relevance
9.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.