CVE-2025-4646: A high privilege user is able to create and use a valid admin API token in centreon-web
Published May 13, 2025
·Updated
Incorrect Authorization vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue affects web: from 24.04.0 before 24.04.10, from 24.10.0 before 24.10.4.
Affected Software
3 affected components
Centreon Centreon Web>=24.04.0, <24.04.10, >=24.10.0, <24.10.4
Centreon Centreon Web>=24.04.0<24.04.10
Centreon Centreon Web>=24.10.0<24.10.4
Event History
May 13, 2025
CVE Published
via MITRE·09:17 AM
Data Sourced
via MITRE·09:17 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-4646?
CVE-2025-4646 is classified as a high severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2025-4646?
To fix CVE-2025-4646, update Centreon web to version 24.04.10 or 24.10.4 or later.
3
What versions of Centreon web are affected by CVE-2025-4646?
CVE-2025-4646 affects Centreon web versions from 24.04.0 before 24.04.10 and from 24.10.0 before 24.10.4.
4
What type of vulnerability is CVE-2025-4646?
CVE-2025-4646 is an Improper Privilege Management vulnerability.
5
Can CVE-2025-4646 lead to data breaches?
Yes, CVE-2025-4646 could allow unauthorized users to escalate their privileges, potentially leading to data breaches.