Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.3, from 24.04.0 before 24.04.3.
References
| Link | Resource |
|---|---|
| https://github.com/centreon/centreon/releases | Release Notes |
| https://thewatch.centreon.com/latest-security-bulletins-64/cve-2025-15026-centreon-awie-critical-severity-5357 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
26 Jan 2026, 15:30
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:centreon:awie:*:*:*:*:*:*:*:* | |
| First Time |
Centreon
Centreon awie |
|
| References | () https://github.com/centreon/centreon/releases - Release Notes | |
| References | () https://thewatch.centreon.com/latest-security-bulletins-64/cve-2025-15026-centreon-awie-critical-severity-5357 - Patch, Vendor Advisory |
08 Jan 2026, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
05 Jan 2026, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-05 15:15
Updated : 2026-01-26 15:30
NVD link : CVE-2025-15026
Mitre link : CVE-2025-15026
CVE.ORG link : CVE-2025-15026
JSON object : View
Products Affected
centreon
- awie
CWE
CWE-306
Missing Authentication for Critical Function
