PT-2026-57656 · Centreon · Centreon-Open-Tickets
CVE-2026-14453
·
Published
2026-07-13
·
Updated
2026-07-13
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
centreon-open-tickets (affected versions not specified)
Description
A critical Server-Side Template Injection (SSTI) exists in the centreon-open-tickets module. The issue occurs because the
message confirm field is stored without sanitization and subsequently rendered by the Smarty template engine without an enforced security policy. This allows an authenticated user to inject and execute arbitrary code on the server under the application context, potentially leading to the disclosure of environment secrets and disruption of the Centreon Infra Monitoring platform availability.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centreon-Open-Tickets