A chained CSRF bypass and unrestricted file upload vulnerability in the Plugin File Manager allows an attacker to upload and execute arbitrary PHP code, resulting in Remote Code Execution. This issue affects Pandora FMS: from 777 onwards.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Fixed v800.5 and v805
Workaround
No workaround given by the vendor.
References
History
Thu, 01 Oct 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pandora Fms
Pandora Fms pandora Fms |
|
| Vendors & Products |
Pandora Fms
Pandora Fms pandora Fms |
Thu, 01 Oct 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A chained CSRF bypass and unrestricted file upload vulnerability in the Plugin File Manager allows an attacker to upload and execute arbitrary PHP code, resulting in Remote Code Execution. This issue affects Pandora FMS: from 777 onwards. | |
| Title | CSRF Bypass Leading to Remote Code Execution via Unrestricted File Upload in Plugin File Manager | |
| Weaknesses | CWE-352 CWE-434 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: PandoraFMS
Published:
Updated: 2026-10-01T09:27:46.696Z
Reserved: 2026-07-21T06:52:17.076Z
Link: CVE-2026-64947
No data.
Status : Received
Published: 2026-10-01T10:17:15.917
Modified: 2026-10-01T10:17:15.917
Link: CVE-2026-64947
No data.
OpenCVE Enrichment
Updated: 2026-10-01T11:00:06Z