CVE-2025-12519

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/01/2026
Last modified:
26/01/2026

Description

Missing Authorization vulnerability in Centreon Infra Monitoring (Administration parameters API endpoint modules) allows Accessing Functionality Not Properly Constrained by ACLs, resulting in Information Disclosure like downtime or acknowledgement configurations. This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.15, from 24.04.0 before 24.04.19.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:* 24.04.0 (including) 24.04.19 (excluding)
cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:* 24.10.0 (including) 24.10.15 (excluding)
cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:* 25.10.0 (including) 25.10.2 (excluding)