Skip to main content
Security Bulletin

April 2026 monthly security bulletin for Centreon Infra Monitoring - HIGH

  • May 12, 2026
  • 0 replies
  • 61 views

lpinsivy
Centreonian
Forum|alt.badge.img+21

 Publication date: May 12th, 2026

 

Component: centreon-anomaly-detection

List of vulnerabilities: 1

Description: SQL injection via string concatenation across legacy PHP files

Reference: N/A

CVSS: 8.8

Severity: High

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Anomaly Detection on Central Server:

 


Component: centreon-autodiscovery

List of vulnerabilities: 1

Description: SQL injection via string concatenation across legacy PHP files

Reference: N/A

CVSS: 8.8

Severity: High

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Auto Discovery on Central Server:

 


Component: centreon-awie

List of vulnerabilities: 1

Description: SQL injection via string concatenation across legacy PHP files

Reference: N/A

CVSS: 8.8

Severity: High

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon AWIE on Central Server:

 


Component: centreon-bam

List of vulnerabilities: 1

Description: SQL injection via string concatenation across legacy PHP files

Reference: N/A

CVSS: 8.8

Severity: High

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon BAM on Central Server:

 


Component: centreon-dsm

List of vulnerabilities: 1

Description: SQL injection via string concatenation across legacy PHP files

Reference: N/A

CVSS: 8.8

Severity: High

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon DSM on Central Server:

 


Component: centreon-license-manager

List of vulnerabilities: 1

Description: SQL injection via string concatenation across legacy PHP files

Reference: N/A

CVSS: 8.8

Severity: High

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon License Manager on Central Server:

 


Component: centreon-map

List of vulnerabilities: 2

Description: SQL injection via string concatenation across legacy PHP files

Reference: N/A

CVSS: 8.8

Severity: High

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Map on Central Server:

 

Description: XSS in images by altering the SVG

Reference: N/A

CVSS: 6.8

Severity: Medium

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Map on Central Server:

 


Component: centreon-mbi

List of vulnerabilities: 1

Description: Command injection via dos2unix exec

Reference: N/A

CVSS: 8.8

Severity: High

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon MBI on Central Server:

 


Component: centreon-open-tickets

List of vulnerabilities: 1

Description: SQL injection via string concatenation across legacy PHP files

Reference: N/A

CVSS: 8.8

Severity: High

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Open Tickets on Central Server:

:index_vers_la_droite: To ensure you do not lose any customization that might have been done to your OpenTicket provider, please make sure to create a backup of your configuration before performing update!

 

 

Stay ahead of potential threats by subscribing to the Security Bulletin section. You’ll receive instant notifications whenever a new bulletin is published, ensuring your infrastructure remains secure and up to date.