CVE-2026-2751Disclosure(centreon / centreon_web)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch centreon centreon_web systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web on Central Server on Linux (Service Dependencies modules) allows Blind SQL Injection.This issue affects Centreon Web on Central Server before 25.10.8, 24.10.20, 24.04.24.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • centreon_web

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • Peaked 3d ago at 3 mentions (2026-02-27); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
centreon_web

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-02-27: 3Mentions · 2026-03-04: 1Mentions · 2026-03-07: 1Mentions · 2026-03-10: 1PoC Mentioned / Linked · 2026-03-07: 1Patch / Workaround · 2026-03-07: 1Technical Details · 2026-02-27: 3Technical Details · 2026-03-04: 1Technical Details · 2026-03-07: 1Technical Details · 2026-03-10: 102-2703-0403-0703-10
Signal classification1 categories
Disclosure
6100.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-273
Disclosure3
2026-03-041
Disclosure1
2026-03-071
Disclosure1
2026-03-101
Disclosure1
Full discourse6 posts
  • Carlos Vieira (lynx)@carlos_crowsec
    Disclosure

    Yesterday our team disclosed an RCE (CVE-2026-2749) in Centreon, along with a few other vulnerabilities. Full details are available in our blog post. The issues were responsibly reported to Centreon, which acknowledged them and released fixes for all affected versions. This resulted in three CVEs: CVE-2026-2749, CVE-2026-2751, and CVE-2026-2750. The RCE has a CVSS score of 9.9. Link: https://hakaisecurity.io/en-deep-looking-into-centreon/research-blog/

    Post summary

    The team disclosed a high‑severity RCE (CVE‑2026‑2749) in Centreon, with additional CVEs identified, and Centreon has released fixes for all affected versions.

    26034103.3K
    3.0K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Centreon Web, Blind SQL Injection, #CVE-2026-2751 (High) https://dailycve.com/centreon-web-blind-sql-injection-cve-2026-2751-high/

    Post summary

    The tweet announces a newly discovered high‑severity blind SQL injection issue in Centreon Web (CVE‑2026‑2751) but does not provide details on exploitation, patches, or false‑positive claims.

    0000037
    167 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2751 (CVSS:8.3, HIGH) is Awaiting Analysis. Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web ..https://nvd.nist.gov/vuln/detail/CVE-2026-2751 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-2751, a high‑severity blind SQL injection in Centreon Web, providing technical details but no evidence of exploitation or patch availability.

    0000032
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2751 Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web on Central Server on Linux (Service Dependencies… https://www.cve.org/CVERecord?id=CVE-2026-2751

    Post summary

    A blind SQL injection vulnerability (CVE-2026-2751) has been disclosed in Centreon Centreon Web, affecting Service Dependencies deletion through unsanitized array keys.

    00000125
    56.6K followersView on X
  • CVETodo@CveTodo
    Disclosure

    - **Exploitation Method:** An attacker sends specially crafted requests to the deletion endpoint, injecting malicious SQL code via the unsanitized array keys. #Cybersecurity #CVE #HighSeverity #SecurityAlert #SQLInjection #Linux https://cvetodo.com/cve/CVE-2026-2751

    Post summary

    The post announces a new SQL injection vulnerability (CVE‑2026‑2751) that allows malicious SQL code to be injected via unsanitized array keys in a deletion endpoint.

    0000038
    20 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-2751 - High Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web on Central Server on Linux (Service Dependencies modules) allows Blind S... https://www.thehackerwire.com/vulnerability/CVE-2026-2751/ https://t.co/NxILPsfnXp

    Post summary

    The tweet discloses CVE‑2026‑2751, a blind SQL injection flaw in Centreon's Service Dependencies module, without mentioning PoC, exploit code, or patch details, and no evidence of active exploitation.

    0000048
    119 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcentreoncentreon_web---

Explore more