CVE-2026-14453 is a critical Server-Side Template Injection (SSTI) vulnerability in Centreon's centreon-open-tickets module. The message_confirm field is stored without sanitization and rendered via Smarty with no security policy enabled, allowing any authenticated user to inject and execute arbitrary code on the server. This results in disclosure of environment secrets and could impact platform availabil [truncated]
A critical SQL injection vulnerability exists in Centreon's Awie export modules, affecting multiple versions. This issue allows unauthenticated users to inject malicious SQL, potentially leading to severe consequences. Centreon Infra Monitoring versions 25.10.0 before 25.10.2, 24.10.0 before 24.10.3, and 24.04.0 before 24.04.3 are impacted. The vulnerability has a CVSS score of 9.8, indicating critical se [truncated]
A critical vulnerability was found in Centreon's Awie module, allowing attackers to access functionality not properly constrained by ACLs due to missing authentication for a critical function. This issue affects Infra Monitoring versions from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.3, and from 24.04.0 before 24.04.3. The vulnerability has a CVSS score of 9.8, indicating critical severity. Defend [truncated]
A high-severity OS Command Injection vulnerability exists in Centreon Infra Monitoring's backup configuration setup, allowing users with high privileges to inject custom instructions. This issue affects multiple versions of Centreon Infra Monitoring, including 25.10.0 before 25.10.2, 24.10.0 before 24.10.15, and 24.04.0 before 24.04.19. The vulnerability has a CVSS score of 7.2 and is classified as HIGH. [truncated]