Centreon · Centreon Infra Monitoring · CVE-2026-2744
**Name of the Vulnerable Software and Affected Versions**
Centreon Infra Monitoring versions 24.04, 24.10, and 25.10
**Description**
A blind time-based SQL injection exists in the Service Dependencies page of Centreon Infra Monitoring. An authenticated user can inject arbitrary SQL via the `select[]` POST array parameter. This allows for full database extraction.
**Recommendations**
Update Centreon Infra Monitoring to a version after 25.10.