cvedb.io
CVE-2025-4649
MEDIUM · CVSS 4.9
EPSS exploitation probability: 0%
Published 2025-05-13T12:15:18.047 · Last modified 2026-06-17T09:33:40.850

Summary

Improper Handling of Exceptional Conditions vulnerability in Centreon web allows Privilege Escalation. ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display all available logs. This issue affects web: from 24.10.3 before 24.10.4, from 24.04.09 before 24.04.10, from 23.10.19 before 23.10.21, from 23.04.24 before 23.04.26.

Affected products

centreon — centreon_web

Does this affect you?

Add your gear to cvedb and we'll alert you only when centreon ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.