Publication date: February 25th, 2026
Components: centreon-web
Description: Broken Object Level Authorization in Users Configuration Endpoint allows Information Disclosure to authenticated user.
Reference: CVE-2025-12523
CVSS: 6.5
Severity: Medium
Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Web on Central Server:
These versions include cumulative fixes from prior updates.
If you are using an High Availability Platform, please ensure to follow the Centreon HA Update procedures.
Reporter: N/A
Stay ahead of potential threats by subscribing to the Security Bulletin section. You’ll receive instant notifications whenever a new bulletin is published, ensuring your infrastructure remains secure and up to date.
