CVE-2025-15026: Centreon Awie
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.3, from 24.04.0 before 24.04.3.
Affected products
- Centreon Awie: from 24.04.0, before 24.04.3 (fixed in 24.04.3); from 24.10.0, before 24.10.3 (fixed in 24.10.3); from 25.10.0, before 25.10.2 (fixed in 25.10.2)
Published 2026-01-05. Last modified 2026-10-07.