Junglewise Threat Intelligence

CVE-2026-14453: Centreon centreon-open-tickets SSTI in message_confirm field

CVE-2026-14453 · Severity: critical · CVSS 9.6 · Published 2026-07-13

Executive brief

A critical security vulnerability exists in Centreon's ticketing module, which is used for managing IT infrastructure alerts. An attacker with basic user access can execute malicious commands on the server, potentially leading to the theft of sensitive credentials or a complete shutdown of the monitoring platform. This could disrupt an organization's ability to track and respond to IT system failures.

Technical details

A Server-Side Template Injection (SSTI) vulnerability exists in the 'message_confirm' field of the Centreon centreon-open-tickets module. The root cause is the lack of sanitization for user-supplied input which is subsequently rendered by the Smarty template engine without an active security policy. An authenticated attacker with low privileges can exploit this via the network to achieve Remote Code Execution (RCE). This can lead to the disclosure of environment secrets and impact the availability of the monitoring product. Patches are available in versions 24.10.14, 25.10.9, and 26.05.1.

Affected products

  • Centreon Infra Monitoring (centreon-open-tickets) 24.10.0 to 24.10.13, 25.10.0 to 25.10.8

Timeline

  • 2026-07-08: patched: Patched versions 24.10.14 and 25.10.9 released.
  • 2026-07-13: disclosed: CVE-2026-14453 published.

References