CVE-2025-15026: Unauthenticated configuration import allows administrative account creation using AWIE component
Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.3, from 24.04.0 before 24.04.3.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15026?
CVE-2025-15026 is classified as a medium severity vulnerability due to missing authentication for critical functions.
How do I fix CVE-2025-15026?
To fix CVE-2025-15026, upgrade Centreon Infra Monitoring to version 25.10.2 or 24.10.3 or later.
What versions of Centreon Infra Monitoring are affected by CVE-2025-15026?
CVE-2025-15026 affects versions of Centreon Infra Monitoring from 25.10.0 before 25.10.2 and from 24.10.0 before 24.10.3.
What kind of access is compromised by CVE-2025-15026?
CVE-2025-15026 allows unauthorized access to functionalities not properly constrained by access control lists (ACLs).
Is CVE-2025-15026 a widespread vulnerability?
The impact of CVE-2025-15026 may vary depending on the deployment of Centreon Infra Monitoring, but any affected system is at risk.