CVE-2025-4646

Incorrect Authorization vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue affects web: from 24.04.0 before 24.04.10, from 24.10.0 before 24.10.4.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:*
cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:*

History

22 Oct 2025, 14:13

Type Values Removed Values Added
References () https://github.com/centreon/centreon/releases - () https://github.com/centreon/centreon/releases - Release Notes
References () https://thewatch.centreon.com/latest-security-bulletins-64/cve-2024-55572-centreon-web-high-severity-4460 - () https://thewatch.centreon.com/latest-security-bulletins-64/cve-2024-55572-centreon-web-high-severity-4460 - Vendor Advisory
First Time Centreon
Centreon centreon Web
CPE cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:*

08 Oct 2025, 10:15

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de administración incorrecta de privilegios en la web de Centreon (módulos de formulario de creación de tokens de API) permite la escalada de privilegios. Este problema afecta a la web: desde la versión 24.04.0 hasta la 24.04.10, desde la versión 24.10.0 hasta la 24.10.4.
Summary (en) Improper Privilege Management vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue affects web: from 24.04.0 before 24.04.10, from 24.10.0 before 24.10.4. (en) Incorrect Authorization vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue affects web: from 24.04.0 before 24.04.10, from 24.10.0 before 24.10.4.
CWE CWE-269 CWE-863

13 May 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-13 10:15

Updated : 2025-10-22 14:13


NVD link : CVE-2025-4646

Mitre link : CVE-2025-4646

CVE.ORG link : CVE-2025-4646


JSON object : View

Products Affected

centreon

  • centreon_web
CWE
CWE-863

Incorrect Authorization