Rapid7

module

Centreon authenticated command injection leading to RCE via broker engine "reload" parameter

Disclosed
Sep 24, 2025
Created
Nov 5, 2025

Description

Centreon is a platform designed to monitor your cloud and on-premises infrastructure.
This module exploits an command injection vulnerability using the `broker engine reload` setting
on the poller configuration page of the Centreon web application. Injecting a malcious payload
at the `broker engine reload` parameter and restarting the poller triggers this vulnerability.
You need have admin access at the Centreon Web application in order to execute this RCE.
This issue affects all Centreon editions >= `19.10.0` and it is fixed in Centreon Web versions
`24.10.13`, `24.04.18` and `23.10.28`.

Author

h00die-gr3y [email protected]

Platform

Linux,Unix

Architectures

cmd

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':


msf > use exploit/linux/http/centreon_auth_rce_cve_2025_5946
msf exploit(centreon_auth_rce_cve_2025_5946) > show targets
...targets...
msf exploit(centreon_auth_rce_cve_2025_5946) > set TARGET < target-id >
msf exploit(centreon_auth_rce_cve_2025_5946) > show options
...show and set options...
msf exploit(centreon_auth_rce_cve_2025_5946) > exploit

Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.