Skip to main content

August 2026 monthly security bulletin for Centreon Infra Monitoring

  • September 9, 2026
  • 0 replies
  • 45 views

Forum|alt.badge.img

Component: centreon-autodiscovery

List of vulnerabilities: 1

Description: Defense-in-depth: parameterized batch insert for rule contact & contactgroup relations

Reference: N/A

CVSS: 0

Severity: Low

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Autodiscovery on Central Server:


Component: centreon-map

List of vulnerabilities: 8

Description: Validate resource ACL on save and gate the editor mx-views endpoints

Reference: N/A

CVSS: 8.1

Severity: High

Description: Remove unauthenticated access-rule endpoints

Reference: N/A

CVSS: 7.1

Severity: High

Description: Move editor metric/graph selection to the standard API

Reference: N/A

CVSS: 6.5

Severity: Medium

Description: Scope geoview resource reads to the geoview

Reference: N/A

CVSS: 6.5

Severity: Medium

Description: Gate the map and geoview import endpoints

Reference: N/A

CVSS: 6.5

Severity: Medium

Description: Scope standard-map resource reads to the map/view

Reference: N/A

CVSS: 6.5

Severity: Medium

Description: Restrict map access-rule assignment on import to the caller's ACL groups

Reference: N/A

CVSS: 4.3

Severity: Medium

Description: Restrict the resource-synchronizer reload endpoint

Reference: N/A

CVSS: 4.3

Severity: Medium

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Map on Central Server:


Component: centreon-mbi

List of vulnerabilities: 3

Description: SQL injection via string concatenation and raw access-group lists (follow-up to MON-195895)

Reference: N/A

CVSS: 8.8

Severity: High

Description: Path traversal via file functions in centreon-bi-server download endpoints

Reference: N/A

CVSS: 6.5

Severity: Medium

Description: XSS via unescaped output in legacy forms/widgets + remove unused dhtmlx library

Reference: N/A

CVSS: 6.1

Severity: Medium

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Mbi on Central Server:


Component: centreon-web

List of vulnerabilities: 4

Description: SQL injection, XSS & disabled TLS verification across legacy PHP files

Reference: N/A

CVSS: 7

Severity: High

Description: Frontend JS / TS (DOM XSS, eval, open redirect, test-only SQLi/path traversal)

Reference: N/A

CVSS: 7

Severity: High

Description: Fix critical issue in robrichards/xmlseclibs

Reference: N/A

CVSS: 7

Severity: High

Description: Defense-in-depth: JS/DOM/SQL output hardening in legacy header, custom-view widget & KB services

Reference: N/A

CVSS: 0

Severity: Low

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Web on Central Server: