CVE-2025-8432 Details
Description
Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within Scripts by CentreonBI user account on the MBI server This issue affects Infra Monitoring: from 24.10.0 before 24.10.6, from 24.04.0 before 24.04.9, from 23.10.0 before 23.10.15.
A vulnerability exists in Centreon Infra Monitoring versions 24.10.0 prior to 24.10.6, 24.04.0 prior to 24.04.9, and 23.10.0 prior to 23.10.15. This vulnerability, caused by incorrect default permissions in the Centreon MBI modules, allows users to embed scripts within other scripts on the MBI server.
Users can upgrade to Centreon versions 24.10.13, 24.10.9, 25.09.1, or 23.10.15 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 27, 2025CISA-ADP
Assessed Oct 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/centreon/centreon/releases | Centreon | Vendor |
| https://thewatch.centreon.com/latest-security-bulletins-64/cve-2025-8432-centreon-mbi-high-severity-5180 | Centreon |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-276 | Incorrect Default Permissions | Centreon |
Affected Products
| Product | Versions |
|---|---|
| Centreon Infra Monitoring | >= 24.10.0, < 24.10.6 (semver) >= 24.04.0, < 24.04.9 (semver) >= 23.10.0, < 23.10.15 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Centreon |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 30, 2025 | CVE Modified | Centreon |
| Oct 27, 2025 | New CVE Received | Centreon |
Volerion