CVE-2025-8432
8.4Centreon · Infra Monitoring
An incorrect default permissions vulnerability in Centreon Infra Monitoring MBI modules allows an authenticated CentreonBI user to embed unauthorized scripts within the server environment.
Executive summary
A high-severity incorrect permissions vulnerability in Centreon Infra Monitoring could allow an authenticated user to perform unauthorized script injection, leading to potential system compromise.
Vulnerability
The vulnerability involves incorrect default permissions (CWE-276) within the MBI modules, allowing an attacker with high-level privileges, specifically the CentreonBI user account, to embed scripts within other scripts.
Business impact
This vulnerability poses a significant risk to the integrity and availability of the monitoring infrastructure. With a CVSS score of 8.4, the flaw permits high-privilege users to execute arbitrary code or modify system behavior, which could result in unauthorized data access, lateral movement within the network, or complete control over the monitoring platform.
Remediation
Immediate Action: Update Centreon Infra Monitoring to the patched versions specified in the vendor security bulletin to resolve the permission flaw.
Proactive Monitoring: Review system access logs for any suspicious script modifications or unusual activity originating from the CentreonBI service account.
Compensating Controls: Restrict access to the MBI module interface to only essential personnel and enforce the principle of least privilege for all service accounts.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the CVSS score of 8.4, this vulnerability represents a significant risk to administrative environments. Organizations utilizing Centreon Infra Monitoring must prioritize applying the provided security patches to all affected instances immediately to prevent potential exploitation by malicious or compromised internal accounts.
More Centreon CVEs
Sources
Originally found and disclosed by Stago, per the CVE Program record.