Description
Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of event responses via a forged GET request when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.
Published: 2026-10-01
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized event response deletion via CSRF by an administrator
Action: Apply Patch
AI Analysis

Impact

Cross‑Site Request Forgery vulnerability permits deletion of event responses via forged GET requests when an authenticated administrator visits a malicious page. Attackers can remove event responses, compromising event integrity and audit trails, representing an unauthorized data deletion flaw (CWE‑352).

Affected Systems

Pandora FMS versions 777 and later are affected until patched to v8.05 or v8.00.5, which includes the fix.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity. EPSS is not reported, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. However, because the flaw requires an authenticated administrator to be tricked into visiting a malicious site, attackers can achieve unauthorized data deletion; exploitation is straightforward once the admin is lured, making the risk significant for entities relying on Pandora FMS event logging.

Generated by OpenCVE AI on October 1, 2026 at 10:35 UTC.

Remediation

Vendor Solution

Fixed v805 an v800.5


OpenCVE Recommended Actions

  • Upgrade Pandora FMS to version 8.05 or 8.00.5, which resolves the CSRF flaw.
  • Apply CSRF protection on the event‑response deletion endpoint, such as requiring a POST request with a valid token.
  • If an upgrade cannot be performed immediately, restrict administrative sessions or block the deletion URL to prevent accidental CSRF exploitation until proper controls are in place.

Generated by OpenCVE AI on October 1, 2026 at 10:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Pandora Fms
Pandora Fms pandora Fms
Vendors & Products Pandora Fms
Pandora Fms pandora Fms

Thu, 01 Oct 2026 09:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of event responses via a forged GET request when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.
Title CSRF in Event Response Deletion
Weaknesses CWE-352
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/S:N/AU:Y/R:U/V:C/RE:L/U:Amber'}


Subscriptions

Pandora Fms Pandora Fms
cve-icon MITRE

Status: PUBLISHED

Assigner: PandoraFMS

Published:

Updated: 2026-10-01T15:05:25.254Z

Reserved: 2026-03-26T10:40:59.131Z

Link: CVE-2026-34189

cve-icon Vulnrichment

Updated: 2026-10-01T15:05:20.362Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T10:17:15.407

Modified: 2026-10-01T16:17:42.710

Link: CVE-2026-34189

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T10:45:07Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)