CVE-2025-15026

9.8

Centreon · Infra Monitoring

A missing authentication vulnerability in the Centreon Infra Monitoring Awie import module allows unauthenticated attackers to access functionality without proper ACL enforcement.

Executive summary

A critical authentication bypass vulnerability in the Centreon Infra Monitoring Awie import module allows unauthenticated remote attackers to achieve full system compromise.

Vulnerability

The vulnerability is a missing authentication for critical function (CWE-306) within the Awie import module. This flaw allows an unauthenticated, remote attacker to interact with sensitive import features that should be restricted by access control lists.

Business impact

With a CVSS score of 9.8, this vulnerability represents a critical risk to organizational infrastructure. Successful exploitation allows an attacker to bypass security controls, potentially leading to unauthorized data access, modification of monitoring configurations, or full system takeover. Such an incident would likely result in severe operational disruption and potential compromise of the wider network managed by the monitoring platform.

Remediation

Immediate Action: Upgrade Centreon Infra Monitoring to versions 25.10.2, 24.10.3, 24.04.3, or later to apply the necessary authentication checks.

Proactive Monitoring: Review web server and application access logs for unusual traffic targeting the Awie import module endpoints or unauthorized administrative actions.

Compensating Controls: Implement strict network segmentation or Web Application Firewall (WAF) rules to restrict access to the Centreon management interface to trusted IP addresses only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability, combined with the lack of required authentication for exploitation, necessitates immediate patching. Organizations should prioritize updating their Centreon Infra Monitoring deployments to the fixed versions identified above to eliminate the risk of remote unauthorized access.

More Centreon CVEs

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Analyst report written
  4. Fix documented version 25.10.2 per CVE record

Sources

Originally found and disclosed by marceloQJ, per the CVE Program record.