← Vulnerability feed

Vulnerability record · CVE-2024-23118 · published 1 April 2024

CVE-2024-23118: Centreon updateContactHostCommands SQL injection leads to remote code execution

Centreon · Centreon Web

Centreon's updateContactHostCommands function builds SQL queries from user-supplied input without proper validation, allowing SQL injection. Because the injection can be chained into code execution, an authenticated attacker can run arbitrary code as the service account on affected Centreon installations.

7.2 CVSS 3.0 High EPSS 53% · top 1.0% CWE-89 · SQL injection
7.2CVSS 3.0 base score
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the updateContactHostCommands function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-22298.

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityRemote code execution with a high EPSS score, though exploitation requires authenticated access with elevated privileges.

What it is

Centreon's updateContactHostCommands function builds SQL queries from user-supplied input without proper validation, allowing SQL injection. Because the injection can be chained into code execution, an authenticated attacker can run arbitrary code as the service account on affected Centreon installations.

Impact

An attacker gains arbitrary code execution in the context of the Centreon service account, giving full control over the application's data and the host privileges of that account.

Attack surface

Reachable over the network through the Centreon web interface; the CVSS vector (AV:N/PR:H) and the advisory state that authentication is required and no user interaction is needed.

Exploitation

Not listed in CISA KEV and no public exploit is referenced; EPSS is high at roughly 0.53 (98.9th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Apply the vendor patch referenced in the Zero Day Initiative advisory ZDI-24-114.
  • Restrict access to the Centreon web interface to trusted management networks.
  • Enforce least privilege and review accounts with the high privileges needed to reach updateContactHostCommands.
  • Audit and monitor database accounts used by Centreon for unexpected query patterns or privilege use.

Detection

  • Monitor Centreon web and application logs for anomalous requests to endpoints invoking updateContactHostCommands.
  • Alert on SQL error strings or unusual query patterns in Centreon database logs.
  • Watch for unexpected child processes or command execution spawned by the Centreon service account.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-23118 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-2751Centreon web sql injection vulnerabilityBlind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web on Central Server on Linux (S…EPSS 0.50%9.8CVE-2024-32501Centreon web sql injection vulnerabilityA SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x …EPSS 19%9.8CVE-2018-11587Centreon code injection vulnerabilityThere is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.ph…EPSS 4.2%9.8CVE-2018-11589Centreon sql injection vulnerabilityMultiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.php, the i…EPSS 2.1%9.6CVE-2023-51633Centreon web cross-site scripting vulnerabilityCentreon sysName Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on af…EPSS 1.1%9.1CVE-2024-33852Centreon web sql injection vulnerabilityA SQL Injection vulnerability exists in the Downtime component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.…EPSS 0.49%9.1CVE-2024-33853Centreon web sql injection vulnerabilityA SQL Injection vulnerability exists in the Timeperiod component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.0…EPSS 0.49%9.1CVE-2024-33854Centreon web sql injection vulnerabilityA SQL Injection vulnerability exists in the Graph Template component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before …EPSS 0.49%

Source: NIST National Vulnerability Database (record CVE-2024-23118), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.