Remote Code Execution Vulnerability in Pandora FMS Plugin File Manager
CVE-2026-64947

7.5HIGH

Key Information:

Vendor
CVE Published:
1 October 2026

What is CVE-2026-64947?

A vulnerability exists in the Plugin File Manager of Pandora FMS, which allows attackers to leverage a chained CSRF bypass alongside unrestricted file upload permissions. This serious flaw enables malicious individuals to upload and execute arbitrary PHP code on the server, which could lead to full remote code execution. The issue affects product versions from 777 onwards, underscoring the critical need for timely updates and security measures.

Affected Version(s)

Pandora FMS all 777

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gaurish Kauthankar (Argon21) & Mr. Omkar Naik
.