Authorization Flaw in Pandora FMS Data Retrieval Module
CVE-2026-64948

7.1HIGH

Key Information:

Vendor
CVE Published:
1 October 2026

What is CVE-2026-64948?

A security vulnerability in Pandora FMS versions from 777 onwards permits unauthorized cross-group access to the module history due to inadequate authorization controls in the data retrieval process. This flaw allows users from different security groups to access sensitive audit logs, potentially exposing critical operational data and compromising system integrity.

Affected Version(s)

Pandora FMS all 777

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdullah Kareem ("cyberkareem")
.