---
id: CVE-2025-8432
title: "Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within Scripts by\_CentreonBI user account on the MBI server This issue affects Infra Monitoring: from 24.10.0 before 24.10.6,…"
summary: "Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within Scripts by\_CentreonBI user account on the MBI server This issue affects Infra Monitoring: from 24.10.0 before 24.10.6,…"
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-276
published: '2025-10-27'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-8432'
references:
  - url: 'https://github.com/centreon/centreon/releases'
    label: bd4443e6-1eef-43f3-9886-25fc9ceeaae7
  - url: >-
      https://thewatch.centreon.com/latest-security-bulletins-64/cve-2025-8432-centreon-mbi-high-severity-5180
    label: bd4443e6-1eef-43f3-9886-25fc9ceeaae7
tags:
  - nvd
epss: 0.00432
epssPercentile: 0.35485
ingestedAt: '2026-10-08T11:31:27.627Z'
---

## Overview

Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within Scripts by CentreonBI user account on the MBI server This issue affects Infra Monitoring: from 24.10.0 before 24.10.6, from 24.04.0 before 24.04.9, from 23.10.0 before 23.10.15.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
