CVE-2026-14453: Critical SSTI to RCE in Centreon Open Tickets (CVSS 9.6)
ID: a8967abf-9160-5c6d-bf4c-90c7a0dcc093
STIX ID: report--a8967abf-9160-5c6d-bf4c-90c7a0dcc093
Feed Name: CosmicBytez Labs
Threat Score
A critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module (CVE-2026-14453, CVSS 9.6) allows low-privilege authenticated users to inject Smarty template directives into the message_confirm field, causing server-side template rendering to execute arbitrary code (RCE); the advisory provides technical analysis, detection indicators, and mitigations including patching, disabling the module, and WAF rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
