CVE-2025-4646: Centreon Web

High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.

Incorrect Authorization vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue affects web: from 24.04.0 before 24.04.10, from 24.10.0 before 24.10.4.

Affected products

  • Centreon Centreon Web: from 24.04.0, before 24.04.10 (fixed in 24.04.10); from 24.10.0, before 24.10.4 (fixed in 24.10.4)

Published 2025-05-13. Last modified 2026-06-17.