CVE-2019-17646: Centreon

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

An issue was discovered in Centreon before 18.10.8, 19.04.5, and 19.10.2. It provides sensitive information via an unauthenticated direct request for api/external.php?object=centreon_metric&action=listByService.

Affected products

  • Centreon Centreon: from 18.0.0, before 18.10.8 (fixed in 18.10.8); from 19.04.0, before 19.04.5 (fixed in 19.04.5); from 19.10.0, before 19.10.2 (fixed in 19.10.2)

Published 2020-03-05. Last modified 2026-06-17.