---
id: CVE-2025-5965
title: >-
  In the backup parameters, a user with high privilege is able to concatenate
  custom instructions to the backup setup
summary: >-
  In the backup parameters, a user with high privilege is able to concatenate
  custom instructions to the backup setup. Improper Neutralization of Special
  Elements used in an OS Command ('OS Command Injection') vulnerability in
  Centreon Inf…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: centreon
product: centreon_web
affected:
  - 'centreon_web >= 24.04.0, < 24.04.19'
  - 'centreon_web >= 24.10.0, < 24.10.15'
  - 'centreon_web >= 25.10.0, < 25.10.2'
patched:
  - centreon_web 25.10.2
published: '2026-01-05'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-5965'
references:
  - url: 'https://github.com/centreon/centreon/releases'
    label: bd4443e6-1eef-43f3-9886-25fc9ceeaae7
  - url: >-
      https://thewatch.centreon.com/latest-security-bulletins-64/cve-2025-5965-centreon-web-high-severity-5362
    label: bd4443e6-1eef-43f3-9886-25fc9ceeaae7
tags:
  - nvd
epss: 0.28572
epssPercentile: 0.9808
ingestedAt: '2026-09-30T23:29:32.535Z'
---

## Overview

In the backup parameters, a user with high privilege is able to concatenate custom instructions to the backup setup. Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Backup configuration in the administration setup modules) allows OS Command Injection.This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.15, from 24.04.0 before 24.04.19.

## Affected

- `centreon_web >= 24.04.0, < 24.04.19`
- `centreon_web >= 24.10.0, < 24.10.15`
- `centreon_web >= 25.10.0, < 25.10.2`

## Remediation

Upgrade past the affected range:

- `centreon_web 25.10.2`
