PT-2026-57656 · Centreon · Centreon-Open-Tickets

CVE-2026-14453

·

Published

2026-07-13

·

Updated

2026-07-13

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions centreon-open-tickets (affected versions not specified)
Description A critical Server-Side Template Injection (SSTI) exists in the centreon-open-tickets module. The issue occurs because the message confirm field is stored without sanitization and subsequently rendered by the Smarty template engine without an enforced security policy. This allows an authenticated user to inject and execute arbitrary code on the server under the application context, potentially leading to the disclosure of environment secrets and disruption of the Centreon Infra Monitoring platform availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14453

Affected Products

Centreon-Open-Tickets