Unrestricted File Upload Vulnerability in Pandora FMS by Pandora FMS
CVE-2026-30804

8.6HIGH

Key Information:

Vendor
CVE Published:
13 April 2026

What is CVE-2026-30804?

A security vulnerability in Pandora FMS allows for the unrestricted upload of files that could be potentially harmful. This flaw enables an attacker to execute remote code on the server by uploading malicious files. The issue influences versions ranging from 777 up to 800, highlighting the urgent need for users to update their software to mitigate the risks associated with unauthorized file uploads.

Affected Version(s)

Pandora FMS all 777 <= 800

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pedro J. Núñez-Cacho Fuentes <tunelko@gmail.com>
.