CVE-2019-16405

HIGH

Centreon Web , 18.10.x , 19.04.x , 19.10.x <2.8.30 <18.10.8 <19.04.5 - Remote Code Execution

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2019-16405. PoCs published by TheCyberGeek.

AI-analyzed exploit summary This Metasploit module exploits an authenticated RCE vulnerability in Centreon by manipulating the Macros Expression's default directory to execute system commands as the Apache user. It downloads and executes a payload via curl or wget.

Description

Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code Execution by an administrator who can modify Macro Expression location settings. CVE-2019-16405 and CVE-2019-17501 are similar to one another and may be the same.

Exploits (2)

exploitdb WORKING POC
by TheCyberGeek · rubywebappsphp
https://www.exploit-db.com/exploits/47948

This Metasploit module exploits an authenticated RCE vulnerability in Centreon by manipulating the Macros Expression's default directory to execute system commands as the Apache user. It downloads and executes a payload via curl or wget.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Centreon <= 18.10, 19.04
Auth required
Prerequisites: Valid Centreon credentials · Network access to the target · PHP session token
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 9 stars
by TheCyberGeek · poc
https://github.com/TheCyberGeek/CVE-2019-16405.rb

This repository contains functional exploit code for CVE-2019-16405, an authenticated remote code execution vulnerability in Centreon. The exploit leverages improper input validation in the Macros Expression feature to execute arbitrary commands as the Apache user.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Centreon 19.04, 18.10
Auth required
Prerequisites: Valid Centreon credentials · Network access to the Centreon web interface
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (10)

Core 10
Core References
Exploit, Third Party Advisory x_refsource_misc
https://thecybergeek.co.uk/cves/2019/09/19/CVEs.html
Patch, Third Party Advisory x_refsource_misc
https://github.com/TheCyberGeek/CVE-2019-16405.rb
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://github.com/centreon/centreon/pull/7884
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://github.com/centreon/centreon/pull/7864
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/155999/Centreon-19.04-Remote-Code-Execution.html

Scores

CVSS v3 7.2
EPSS 0.0856
EPSS Percentile 92.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (2)
centreon/centreon 0 - 18.10.8Packagist
centreon/centreon_web < 2.8.30
Published Nov 21, 2019
Tracked Since Feb 18, 2026