← Vulnerability feed

Vulnerability record · CVE-2024-23116 · published 1 April 2024

CVE-2024-23116: Centreon updateLCARelation SQL injection leads to remote code execution

Centreon · Centreon Web

CVE-2024-23116 is a SQL injection in the updateLCARelation function of Centreon, caused by a user-supplied string being used to build SQL queries without proper validation. It is described as a remote code execution vulnerability, meaning successful exploitation can go beyond data access to code execution on the affected installation. Authentication is required, which limits the attacker pool but not the severity for exposed, internet-facing deployments.

7.2 CVSS 3.0 High EPSS 53% · top 1.0% CWE-89 · SQL injection
7.2CVSS 3.0 base score
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the updateLCARelation function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-22296.

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityCVSS 7.2 with network reachability and code execution impact, plus a very high EPSS score, outweigh the authentication requirement.

What it is

CVE-2024-23116 is a SQL injection in the updateLCARelation function of Centreon, caused by a user-supplied string being used to build SQL queries without proper validation. It is described as a remote code execution vulnerability, meaning successful exploitation can go beyond data access to code execution on the affected installation. Authentication is required, which limits the attacker pool but not the severity for exposed, internet-facing deployments.

Impact

An authenticated attacker can execute arbitrary code in the context of the service account, gaining control over the Centreon application and its data. This can lead to full compromise of the monitoring platform and any credentials or systems it manages.

Attack surface

The flaw is reached remotely over the network through the Centreon web interface, per the CVSS vector AV:N. Exploitation requires authentication with high privileges (PR:H) and no user interaction (UI:N).

Exploitation

The record does not list this CVE in CISA KEV and documents no ransomware use. EPSS is high at roughly 0.53 probability (99th percentile), and the only references are the ZDI advisory tagged Patch and Third Party Advisory, so no public exploit code is confirmed by the supplied data.

What to do

  • Apply the vendor patch referenced in the ZDI advisory (ZDI-24-116) as the first action.
  • Restrict network access to the Centreon web interface and avoid exposing it directly to the internet.
  • Enforce least privilege and review which accounts hold the high privileges required to reach updateLCARelation.
  • Monitor and audit administrative accounts for unexpected activity, since exploitation requires authenticated access.
  • Validate and sanitize user-supplied input in updateLCARelation and similar SQL-building functions if custom code is involved.

Detection

  • Review Centreon web and database logs for anomalous SQL queries or errors originating from the updateLCARelation function.
  • Alert on unexpected child processes or command execution spawned by the Centreon service account.
  • Monitor for unusual authenticated sessions, especially from new or unexpected source IPs, against the Centreon web interface.
  • Correlate database query patterns with requests to the updateLCARelation endpoint to spot injection attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-23116 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-2751Centreon web sql injection vulnerabilityBlind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web on Central Server on Linux (S…EPSS 0.50%9.8CVE-2024-32501Centreon web sql injection vulnerabilityA SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x …EPSS 19%9.8CVE-2018-11587Centreon code injection vulnerabilityThere is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.ph…EPSS 4.2%9.8CVE-2018-11589Centreon sql injection vulnerabilityMultiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.php, the i…EPSS 2.1%9.6CVE-2023-51633Centreon web cross-site scripting vulnerabilityCentreon sysName Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on af…EPSS 1.1%9.1CVE-2024-33852Centreon web sql injection vulnerabilityA SQL Injection vulnerability exists in the Downtime component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.…EPSS 0.49%9.1CVE-2024-33853Centreon web sql injection vulnerabilityA SQL Injection vulnerability exists in the Timeperiod component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.0…EPSS 0.49%9.1CVE-2024-33854Centreon web sql injection vulnerabilityA SQL Injection vulnerability exists in the Graph Template component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before …EPSS 0.49%

Source: NIST National Vulnerability Database (record CVE-2024-23116), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.