CVE-2026-14453

Diese Schwachstelle ist eine kritische Serverseitige Vorlageninjektion (SSTI) im Modul centreon-open-tickets von Centreon, die zu einer F…

criticalEPSS 0.8%

Description

This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that leads to Remote Code Execution. The message_confirm field is stored without sanitization and rendered via Smarty with no security policy enabled, allowing any authenticated user, to inject and execute arbitrary code on the server. This results in disclosure of environment secrets and could impact platform availability of Centreon Infra Monitoring product.

Metrics

9.6
Source: nvd-v3
56.5 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.8 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-13 08:19 UTC
CWE-94

Weakness classes (CWE)

  • CWE-94Base

    Improper Control of Generation of Code ('Code Injection')

    The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

    cwe.mitre.org →

References & sources

Linked advisories