Skip to main content
Security Bulletin

May 2026 monthly security bulletin for Centreon Infra Monitoring - MEDIUM

  • May 28, 2026
  • 2 replies
  • 199 views

lpinsivy
Centreonian
Forum|alt.badge.img+21

Publication date: May 28th, 2026

 

Component: centreon-web

List of vulnerabilities: 2

 

Description: Fixed multiple shell injection vulnerabilities in legacy PHP code where database-sourced or insufficiently-validated values are interpolated into shell commands without proper escaping.

Reference: N/A

CVSS: 6.6

Severity: Medium

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Anomaly Detection on Central Server:

 


 

Description: Fixed Content-Disposition HTTP headers in CSV export pages and graph image responses use database-sourced filenames (host names, service descriptions, group names) without proper sanitization or quoting. A double-quote character in a name could break out of the filename value, potentially allowing an attacker to manipulate how browsers interpret the download.

Reference: N/A

CVSS: 3.1

Severity: Low

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Anomaly Detection on Central Server:

 

Stay ahead of potential threats by subscribing to the Security Bulletin section. You’ll receive instant notifications whenever a new bulletin is published, ensuring your infrastructure remains secure and up to date.

 

 

2 replies

Forum|alt.badge.img+10
  • Builder *
  • June 1, 2026

Hello, Please could you give us the specific CVEs for these vulnerabilities?

 

Laurent


lpinsivy
Centreonian
Forum|alt.badge.img+21
  • Author
  • Centreonian
  • June 1, 2026

Hello, Please could you give us the specific CVEs for these vulnerabilities?

 

Laurent

There is no CVE-ID, these are vulnerabilities discovered by our tools and corrected internally.