PT-2026-22338 · Centreon · Centreon

Texugo

·

Published

2026-02-25

·

Updated

2026-03-10

·

CVE-2026-2751

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Centreon versions prior to 25.10.8 Centreon versions prior to 24.10.20 Centreon versions prior to 24.04.24
Description A Blind SQL Injection can occur due to unsanitized array keys during the deletion of Service Dependencies. This issue affects the Centreon Web application on the Central Server running on Linux, specifically within the Service Dependencies modules. The injection is possible because input validation is insufficient when processing array keys, potentially allowing an attacker to manipulate database queries.
Recommendations Update to Centreon version 25.10.8 or later. Update to Centreon version 24.10.20 or later. Update to Centreon version 24.04.24 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2026-04799
CVE-2026-2751

Affected Products

Centreon