CVE-2026-2749

CRITICAL LAB

Centreon Open Tickets <25.10.3 - Path Traversal

Title source: manual
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2026-2749. PoCs published by hakaioffsec, exploitintel, XZ1r0.

AI-analyzed exploit summary The repository contains functional exploit code for multiple Centreon vulnerabilities (CVE-2026-2749, CVE-2026-2750, CVE-2026-2751), including path traversal to RCE, command injection via CLAPI, and blind SQL injection. Each script is well-structured with clear arguments, session handling, and verification steps.

Description

Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10.3, 24.10.8, 24.04.7.

Exploits (3)

nomisec WORKING POC 2 stars
by hakaioffsec · poc
https://github.com/hakaioffsec/Centreon-Exploits-2026

The repository contains functional exploit code for multiple Centreon vulnerabilities (CVE-2026-2749, CVE-2026-2750, CVE-2026-2751), including path traversal to RCE, command injection via CLAPI, and blind SQL injection. Each script is well-structured with clear arguments, session handling, and verification steps.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Centreon <= 25.10.6
Auth required
Prerequisites: valid PHPSESSID cookie · network access to target
devstral-2 · analyzed Mar 03, 2026 Full analysis →
github WORKING POC 1 stars
by exploitintel · pythonpoc
https://github.com/exploitintel/eip-pocs-and-cves/tree/main/CVE-2026-2749

This repository contains functional exploit code for CVE-2026-2749, a path traversal vulnerability in Centreon Open Tickets leading to remote code execution. It includes multiple PoC scripts demonstrating file write, deletion, and RCE via unsanitized `uniqId` parameters.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Centreon Open Tickets < 25.10.3
Auth required
Prerequisites: authenticated user session · network access to target
devstral-2 · analyzed Mar 02, 2026 Full analysis →
github WORKING POC
by XZ1r0 · pythonpoc
https://github.com/XZ1r0/cve-2026-poc-collection/tree/main/other/Centreon-Exploits-2026/CVE-2026-2749

This Python script exploits a path traversal vulnerability in Centreon (CVE-2026-2749) to upload a malicious PHP file, achieving remote code execution (RCE). It leverages an arbitrary file write flaw in the Open Tickets module's upload functionality.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Centreon <= 25.10.6
Auth required
Prerequisites: Valid PHPSESSID cookie · Access to the Centreon web interface
devstral-2 · analyzed May 21, 2026 Full analysis →

Related Analysis

Scores

CVSS v3 9.9
EPSS 0.0014
EPSS Percentile 34.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Lab Environment

EIP LAB Lab screenshot
vulnerable docker pull ghcr.io/exploitintel/cve-2026-2749-vulnerable:latest

Details

Status published
Products (1)
Centreon/None all - 25.10.3, 24.10.8, 24.04.7
Published Feb 27, 2026
Tracked Since Feb 27, 2026