---
id: CVE-2025-15026
title: >-
  Missing Authentication for Critical Function vulnerability in Centreon Infra
  Monitoring centreon-awie (Awie import module) allows Accessing Functionality
  Not Properly Constrained by ACLs.


  This issue affects Infra Monitoring: from 25.10.…
summary: >-
  Missing Authentication for Critical Function vulnerability in Centreon Infra
  Monitoring centreon-awie (Awie import module) allows Accessing Functionality
  Not Properly Constrained by ACLs.


  This issue affects Infra Monitoring: from 25.10.…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-306
vendor: centreon
product: awie
affected:
  - 'awie >= 24.04.0, < 24.04.3'
  - 'awie >= 24.10.0, < 24.10.3'
  - 'awie >= 25.10.0, < 25.10.2'
patched:
  - awie 25.10.2
published: '2026-01-05'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15026'
references:
  - url: 'https://github.com/centreon/centreon/releases'
    label: bd4443e6-1eef-43f3-9886-25fc9ceeaae7
  - url: >-
      https://thewatch.centreon.com/latest-security-bulletins-64/cve-2025-15026-centreon-awie-critical-severity-5357
    label: bd4443e6-1eef-43f3-9886-25fc9ceeaae7
tags:
  - nvd
epss: 0.00424
epssPercentile: 0.34342
ingestedAt: '2026-09-30T23:29:32.540Z'
---

## Overview

Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.3, from 24.04.0 before 24.04.3.

## Affected

- `awie >= 24.04.0, < 24.04.3`
- `awie >= 24.10.0, < 24.10.3`
- `awie >= 25.10.0, < 25.10.2`

## Remediation

Upgrade past the affected range:

- `awie 25.10.2`
