CVE-2026-2750

CRITICAL

Centreon Open Tickets <25.10 - Input Validation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2026-2750. PoCs published by hakaioffsec, TreasureBoy520, XZ1r0.

AI-analyzed exploit summary The repository contains functional exploit code for multiple Centreon vulnerabilities (CVE-2026-2749, CVE-2026-2750, CVE-2026-2751), including path traversal leading to RCE, command injection via CLAPI, and blind SQL injection. Each exploit is well-structured with clear arguments, session handling, and verification steps.

Description

Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tickets modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10; 24.10;24.04.

Exploits (3)

github WORKING POC 9 stars
by hakaioffsec · pythonpoc
https://github.com/hakaioffsec/Centreon-Exploits-2026

The repository contains functional exploit code for multiple Centreon vulnerabilities (CVE-2026-2749, CVE-2026-2750, CVE-2026-2751), including path traversal leading to RCE, command injection via CLAPI, and blind SQL injection. Each exploit is well-structured with clear arguments, session handling, and verification steps.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Centreon <= 25.10.6
Auth required
Prerequisites: valid PHPSESSID cookie · network access to target
mistral-large-3 · analyzed May 01, 2026 Full analysis →
github WORKING POC
by TreasureBoy520 · pythonpoc
https://github.com/TreasureBoy520/cve-2026-poc-collection/tree/main/other/Centreon-Exploits-2026/CVE-2026-2750

This exploit leverages an OS command injection vulnerability in Centreon's CLAPI `generatetraps` action via improperly sanitized input in the MIB file path. The PoC uploads a crafted MIB file with a command injection payload and triggers it through the `passthru()` function in the `generatetraps` endpoint.

Classification
Working Poc 98%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Centreon <= 25.10.6
Auth required
Prerequisites: Valid PHPSESSID session cookie (authenticated access) · Centreon installation with centreon-open-tickets module enabled · Network access to the Centreon web interface
mistral-large-3 · analyzed Aug 03, 2026 Full analysis →
github WORKING POC
by XZ1r0 · pythonpoc
https://github.com/XZ1r0/cve-2026-poc-collection/tree/main/other/Centreon-Exploits-2026/CVE-2026-2750

This Python script exploits CVE-2026-2750, a command injection vulnerability in Centreon's CLAPI generatetraps functionality. It uploads a malicious MIB file via the open-tickets module and triggers command execution through the CLAPI endpoint.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Centreon <= 25.10.6
Auth required
Prerequisites: valid PHPSESSID cookie · access to Centreon web interface
mistral-large-3 · analyzed May 21, 2026 Full analysis →

Scores

CVSS v3 9.1
EPSS 0.0030
EPSS Percentile 22.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20
Status published
Products (2)
Centreon/Centreon Open Tickets on Central Server all - 25.10; 24.10;24.04
centreon/web < 24.04.24
Published Feb 27, 2026
Tracked Since Feb 27, 2026