Home

Description

Incorrect Authorization vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue affects web: from 24.04.0 before 24.04.10, from 24.10.0 before 24.10.4.

PUBLISHED Reserved 2025-05-13 | Published 2025-05-13 | Updated 2025-10-08 | Assigner Centreon




HIGH: 7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-863 Incorrect Authorization

Product status

Default status
unaffected

24.04.0 (semver) before 24.04.10
affected

24.10.0 (semver) before 24.10.4
affected

Credits

Floerer from YesWeHack finder

References

thewatch.centreon.com/...572-centreon-web-high-severity-4460 vendor-advisory

github.com/centreon/centreon/releases release-notes

cve.org (CVE-2025-4646)

nvd.nist.gov (CVE-2025-4646)

Download JSON