Description
Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of alert commands via sequential, unvalidated GET requests when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.
Published: 2026-10-01
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Deletion of Alert Commands
Action: Patch Imminently
AI Analysis

Impact

This vulnerability is a CSRF flaw that allows an attacker who can get an authenticated administrator to visit a malicious page to send a sequence of unvalidated GET requests that delete alert commands. The result is the loss of critical monitoring configuration, potentially disrupting alerting and exposing sensitive data.

Affected Systems

Pandora FMS products from version 777 onward are affected. The vendor has issued fixes in version 800.5 and 805. Administrators running any of these releases should confirm their current version and plan an upgrade to a patched release.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity, and no EPSS score is available. Because the flaw is a CSRF attack that requires the target manager to load a malicious page while authenticated, the attack is constrained to social engineering or credential compromise scenarios. The vulnerability is not listed in the CISA KEV catalog, but the lack of a high CVSS or EPSS does not negate the risk of successful exploitation.

Generated by OpenCVE AI on October 1, 2026 at 10:35 UTC.

Remediation

Vendor Solution

Fixed v800.5 and v805


OpenCVE Recommended Actions

  • Apply the vendor patch to reach version 800.5 or later as indicated by the vendor.
  • If an immediate upgrade is not feasible, configure the system to block external GET requests for alert command deletion and enforce anti‑CSRF token validation.
  • Review all alert command configurations and regenerate them after patching to ensure continued correct monitoring.

Generated by OpenCVE AI on October 1, 2026 at 10:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Pandora Fms
Pandora Fms pandora Fms
Vendors & Products Pandora Fms
Pandora Fms pandora Fms

Thu, 01 Oct 2026 09:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of alert commands via sequential, unvalidated GET requests when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.
Title CSRF in Alert Command Deletion
Weaknesses CWE-352
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/S:N/AU:Y/R:U/V:C/RE:L/U:Amber'}


Subscriptions

Pandora Fms Pandora Fms
cve-icon MITRE

Status: PUBLISHED

Assigner: PandoraFMS

Published:

Updated: 2026-10-01T15:05:03.063Z

Reserved: 2026-03-26T10:40:59.131Z

Link: CVE-2026-34190

cve-icon Vulnrichment

Updated: 2026-10-01T15:02:08.181Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T10:17:15.617

Modified: 2026-10-01T16:17:42.877

Link: CVE-2026-34190

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T10:45:07Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)