Skip to main content
Security Bulletin

CVE-2025-12514 - Centreon Open Tickets - High Severity

  • January 5, 2026
  • 0 replies
  • 262 views

lpinsivy
Centreonian
Forum|alt.badge.img+21

Publication date: December 18th, 2025

Components: centreon-open-tickets

Description: A user with elevated privileges is able to introduce a SQL Injection using the Open-tickets Notification rules configuration parameters.

Reference CVE-2025-12514

CVSS: 7.2 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)

Severity: High

 

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Web on Central Server:

These versions include cumulative fixes from prior updates.

 

:index_vers_la_droite: To ensure you do not lose any customization that might have been done to your OpenTicket provider, please make sure to create a backup of your configuration before performing update!

 

If you are using an High Availability Platform, please ensure to follow the Centreon HA Update procedures.

 

Reporter: Marcelo Quieroz

 

Stay ahead of potential threats by subscribing to the Security Bulletin section. You’ll receive instant notifications whenever a new bulletin is published, ensuring your infrastructure remains secure and up to date.