CVE-2025-15026
9.8Centreon · Infra Monitoring
A missing authentication vulnerability in the Centreon Infra Monitoring Awie import module allows unauthenticated attackers to access functionality without proper ACL enforcement.
Executive summary
A critical authentication bypass vulnerability in the Centreon Infra Monitoring Awie import module allows unauthenticated remote attackers to achieve full system compromise.
Vulnerability
The vulnerability is a missing authentication for critical function (CWE-306) within the Awie import module. This flaw allows an unauthenticated, remote attacker to interact with sensitive import features that should be restricted by access control lists.
Business impact
With a CVSS score of 9.8, this vulnerability represents a critical risk to organizational infrastructure. Successful exploitation allows an attacker to bypass security controls, potentially leading to unauthorized data access, modification of monitoring configurations, or full system takeover. Such an incident would likely result in severe operational disruption and potential compromise of the wider network managed by the monitoring platform.
Remediation
Immediate Action: Upgrade Centreon Infra Monitoring to versions 25.10.2, 24.10.3, 24.04.3, or later to apply the necessary authentication checks.
Proactive Monitoring: Review web server and application access logs for unusual traffic targeting the Awie import module endpoints or unauthorized administrative actions.
Compensating Controls: Implement strict network segmentation or Web Application Firewall (WAF) rules to restrict access to the Centreon management interface to trusted IP addresses only.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this vulnerability, combined with the lack of required authentication for exploitation, necessitates immediate patching. Organizations should prioritize updating their Centreon Infra Monitoring deployments to the fixed versions identified above to eliminate the risk of remote unauthorized access.
More Centreon CVEs
History
- Disclosed CVE record published
- Published in the daily brief critical section
- Analyst report written
- Fix documented version 25.10.2 per CVE record
Sources
Originally found and disclosed by marceloQJ, per the CVE Program record.