Skip to main content

July 2026 monthly security bulletin for Centreon Infra Monitoring

  • August 12, 2026
  • 0 replies
  • 31 views

Forum|alt.badge.img

Component: centreon-anomaly-detection

List of vulnerabilities: 1

Description: SQL injection via raw access-group list in service ACL filter

Reference: N/A

CVSS: 8.8

Severity: High

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Anomaly Detection on Central Server:


Component: centreon-autodiscovery

List of vulnerabilities: 1

Description: SQL injection and unsafe exec() in rule management

Reference: N/A

CVSS: 8.8

Severity: High

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Autodiscovery on Central Server:


Component: centreon-bam

List of vulnerabilities: 1

Description: SQL injection, XSS, info disclosure & command exec in legacy PHP files

Reference: N/A

CVSS: 8.8

Severity: High

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Bam on Central Server:


Component: centreon-mbi

List of vulnerabilities: 1

Description: SQL injection via string concatenation across legacy PHP files (mbi)

Reference: N/A

CVSS: 8.8

Severity: High

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Mbi on Central Server:


Component: centreon-open-tickets

List of vulnerabilities: 2

Description: SQL injection via string concatenation across legacy PHP files

Reference: N/A

CVSS: 8.8

Severity: High

Description: Reflected Cross-Site Scripting (XSS) in Open Tickets Widget Toolbar

Reference: N/A

CVSS: 6.8

Severity: Medium

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Open Tickets on Central Server:


Component: centreon-pp-manager

List of vulnerabilities: 1

Description: SQL injection via string concatenation in installation classes

Reference: N/A

CVSS: 8.8

Severity: High

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Pp Manager on Central Server:


Component: centreon-web

List of vulnerabilities: 13

Description: SQL injection via string concatenation in legacy PHP files

Reference: N/A

CVSS: 8.8

Severity: High

Description: Misc legacy (SQLi + XSS in assorted legacy classes)

Reference: N/A

CVSS: 7

Severity: High

Description: CLAPI (SQLi in command-line API classes)

Reference: N/A

CVSS: 7

Severity: High

Description: Knowledge / Wiki (SQLi + disabled TLS in MediaWiki integration)

Reference: N/A

CVSS: 7

Severity: High

Description: Pollers / Broker (SQLi + unserialize RCE in engine/broker/remote config)

Reference: N/A

CVSS: 7

Severity: High

Description: Downtime / Acknowledgement (SQLi in RT downtime & ack)

Reference: N/A

CVSS: 7

Severity: High

Description: Hosts (SQLi in host & hostgroup data access)

Reference: N/A

CVSS: 7

Severity: High

Description: Services (SQLi + XSS in service / servicegroup screens)

Reference: N/A

CVSS: 7

Severity: High

Description: Timeperiods (SQLi in timeperiod config & rendering)

Reference: N/A

CVSS: 7

Severity: High

Description: Users / Sessions / Auth (SQLi in auth & session)

Reference: N/A

CVSS: 7

Severity: High

Description: Legacy API classes (SQLi in `www/api/class`)

Reference: N/A

CVSS: 7

Severity: High

Description: Common helpers / Forms (SQLi + XSS + RCE + TLS in shared utilities)

Reference: N/A

CVSS: 7

Severity: High

Description: ORM / DB layer (SQLi in generic data-access plumbing)

Reference: N/A

CVSS: 7

Severity: High

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Web on Central Server: