This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.3, from 24.04.0 before 24.04.3.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 26 Jan 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Centreon awie
|
|
| CPEs | cpe:2.3:a:centreon:awie:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Centreon awie
|
Thu, 08 Jan 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 06 Jan 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Centreon
Centreon centreon |
|
| Vendors & Products |
Centreon
Centreon centreon |
Tue, 06 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Jan 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.3, from 24.04.0 before 24.04.3. | |
| Title | Unauthenticated configuration import allows administrative account creation using AWIE component | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Centreon
Published:
Updated: 2026-01-08T15:42:06.582Z
Reserved: 2025-12-22T09:36:24.995Z
Link: CVE-2025-15026
Updated: 2026-01-05T21:19:55.900Z
Status : Analyzed
Published: 2026-01-05T15:15:44.177
Modified: 2026-01-26T15:30:46.243
Link: CVE-2025-15026
No data.
OpenCVE Enrichment
Updated: 2026-01-06T14:17:13Z