Centreon Web Blind SQL Injection Vulnerability in Service Dependencies Deletion

Vulnerability

A blind SQL injection vulnerability has been identified in the Centreon Web application running on Central Server on Linux, specifically within the Service Dependencies module. This vulnerability arises from unsanitized array keys during the deletion of service dependencies, allowing for manipulation of SQL queries. The issue affects Centreon Web on Central Server versions prior to 25.10.8, as well as 24.10.20 and 24.04.24.

Impact

Exploitation of this vulnerability allows for blind SQL injection, where an attacker can manipulate SQL queries and potentially access or modify database information without being able to see the results of their queries directly.

Added: Feb 27, 2026, 2:40 PM
Updated: Feb 27, 2026, 3:19 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
3.1
exploitability
4.8
remediation
0.0
relevance
3.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.