Skip to main content
Security Bulletin

Security bulletin for Centreon Infra Monitoring - Centreon 24.10.31 / 25.10.18

  • October 1, 2026
  • 0 replies
  • 98 views

Forum|alt.badge.img

Component: centreon-gorgone

List of vulnerabilities: 1

Description: Gorgone action whitelist bypass allows arbitrary OS command execution as centreon-gorgone

Reference: CVE-2026-93035

CVSS: 8.8

Severity: High

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Gorgone on Central Server:


Component: centreon-monitoring-agent

List of vulnerabilities: 1

Description: centagent.exe service path is not protected with quotes - CMA (24.10.x Windows)

Reference: N/A

CVSS: 7.8

Severity: High

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Monitoring Agent on Central Server:


Component: centreon-open-tickets

List of vulnerabilities: 1

Description: DOM XSS & test-tooling path traversal in HTML/JS files

Reference: N/A

CVSS: 5

Severity: Medium

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Open Tickets on Central Server:


Component: centreon-web

List of vulnerabilities: 1

Description: Possible Remote Code Execution on centreon installation process

Reference: N/A

CVSS: 10

Severity: Critical

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Web on Central Server: