Remote Code Execution Vulnerability in Pandora FMS Plugin File Manager
CVE-2026-64947
7.5HIGH
What is CVE-2026-64947?
A vulnerability exists in the Plugin File Manager of Pandora FMS, which allows attackers to leverage a chained CSRF bypass alongside unrestricted file upload permissions. This serious flaw enables malicious individuals to upload and execute arbitrary PHP code on the server, which could lead to full remote code execution. The issue affects product versions from 777 onwards, underscoring the critical need for timely updates and security measures.
Affected Version(s)
Pandora FMS all 777
References
CVSS V4
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Gaurish Kauthankar (Argon21) & Mr. Omkar Naik
