Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.3, from 24.04.0 before 24.04.3.
References
| Link | Resource |
|---|---|
| https://github.com/centreon/centreon/releases | Release Notes |
| https://thewatch.centreon.com/latest-security-bulletins-64/cve-2025-15026-centreon-awie-critical-severity-5357 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-01-05 15:15
Updated : 2026-01-26 15:30
NVD link : CVE-2025-15026
Mitre link : CVE-2025-15026
CVE.ORG link : CVE-2025-15026
JSON object : View
Products Affected
centreon
- awie
CWE
CWE-306
Missing Authentication for Critical Function
