Improper Handling of Exceptional Conditions vulnerability in Centreon web allows Privilege Escalation. ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display all available logs. This issue affects web: from 24.10.3 before 24.10.4, from 24.04.09 before 24.04.10, from 23.10.19 before 23.10.21, from 23.04.24 before 23.04.26.
History

Wed, 22 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Centreon
Centreon centreon Web
CPEs cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:*
cpe:2.3:a:centreon:centreon_web:24.04.9:*:*:*:*:*:*:*
cpe:2.3:a:centreon:centreon_web:24.10.3:*:*:*:*:*:*:*
Vendors & Products Centreon
Centreon centreon Web

Wed, 15 Oct 2025 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Wed, 15 Oct 2025 13:15:00 +0000

Type Values Removed Values Added
Description Improper Privilege Management vulnerability in Centreon web allows Privilege Escalation. ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display all available logs. This issue affects web: from 24.10.3 before 24.10.4, from 24.04.09 before 24.04.10, from 23.10.19 before 23.10.21, from 23.04.24 before 23.04.26. Improper Handling of Exceptional Conditions vulnerability in Centreon web allows Privilege Escalation. ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display all available logs. This issue affects web: from 24.10.3 before 24.10.4, from 24.04.09 before 24.04.10, from 23.10.19 before 23.10.21, from 23.04.24 before 23.04.26.
Weaknesses CWE-755

Tue, 13 May 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 13 May 2025 12:00:00 +0000

Type Values Removed Values Added
Description Improper Privilege Management vulnerability in Centreon web allows Privilege Escalation. ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display all available logs. This issue affects web: from 24.10.3 before 24.10.4, from 24.04.09 before 24.04.10, from 23.10.19 before 23.10.21, from 23.04.24 before 23.04.26.
Title ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display all available logs.
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Centreon

Published: 2025-05-13T11:40:23.198Z

Updated: 2025-10-15T13:05:23.113Z

Reserved: 2025-05-13T09:47:58.210Z

Link: CVE-2025-4649

cve-icon Vulnrichment

Updated: 2025-05-13T13:04:43.180Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-13T12:15:18.047

Modified: 2025-10-22T14:05:13.117

Link: CVE-2025-4649

cve-icon Redhat

No data.