Missing Authorization vulnerability in Centreon Infra Monitoring (Administration parameters API endpoint modules) allows Accessing Functionality Not Properly Constrained by ACLs, resulting in Information Disclosure like downtime or acknowledgement configurations. This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.15, from 24.04.0 before 24.04.19.
Metrics
Affected Vendors & Products
References
History
Thu, 08 Jan 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 06 Jan 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Centreon
Centreon centreon |
|
| Vendors & Products |
Centreon
Centreon centreon |
Tue, 06 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Jan 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing Authorization vulnerability in Centreon Infra Monitoring (Administration parameters API endpoint modules) allows Accessing Functionality Not Properly Constrained by ACLs, resulting in Information Disclosure like downtime or acknowledgement configurations. This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.15, from 24.04.0 before 24.04.19. | |
| Title | Information disclosure on Administration parameters API endpoint | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Centreon
Published: 2026-01-05T10:15:08.921Z
Updated: 2026-01-08T15:41:12.866Z
Reserved: 2025-10-30T15:49:52.593Z
Link: CVE-2025-12519
Updated: 2026-01-05T20:28:20.988Z
Status : Awaiting Analysis
Published: 2026-01-05T11:17:39.830
Modified: 2026-01-08T18:09:49.800
Link: CVE-2025-12519
No data.