CSRF Vulnerability in Pandora FMS by Pandora FMS
CVE-2026-34189

5.9MEDIUM

Key Information:

Vendor
CVE Published:
1 October 2026

What is CVE-2026-34189?

A Cross-Site Request Forgery (CSRF) vulnerability present in Pandora FMS allows an attacker to craft a malicious page that can execute unauthorized deletion of event responses when accessed by an authenticated administrator. This threat affects versions from 777 onwards, potentially jeopardizing the integrity of user data. Administrators are advised to implement robust security measures to safeguard against unauthorized actions initiated through seemingly benign interactions.

Affected Version(s)

Pandora FMS all 777

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gaurish Kauthankar (Argon21) & Mr. Omkar Naik
.