Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14376 | Improper Privilege Management vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue affects web: from 24.04.0 before 24.04.10, from 24.10.0 before 24.10.4. |
Wed, 22 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Centreon
Centreon centreon Web |
|
| CPEs | cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Centreon
Centreon centreon Web |
Wed, 08 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 |
Wed, 08 Oct 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Privilege Management vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue affects web: from 24.04.0 before 24.04.10, from 24.10.0 before 24.10.4. | Incorrect Authorization vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue affects web: from 24.04.0 before 24.04.10, from 24.10.0 before 24.10.4. |
| Weaknesses | CWE-863 |
Tue, 13 May 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 May 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Privilege Management vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue affects web: from 24.04.0 before 24.04.10, from 24.10.0 before 24.10.4. | |
| Title | A high privilege user is able to create and use a valid admin API token in centreon-web | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Centreon
Published:
Updated: 2025-10-08T10:00:43.607Z
Reserved: 2025-05-13T08:17:11.709Z
Link: CVE-2025-4646
Updated: 2025-05-13T13:09:21.695Z
Status : Analyzed
Published: 2025-05-13T10:15:29.113
Modified: 2025-10-22T14:13:47.513
Link: CVE-2025-4646
No data.
OpenCVE Enrichment
No data.
EUVD