Description
A chained CSRF bypass and unrestricted file upload vulnerability in the Plugin File Manager allows an attacker to upload and execute arbitrary PHP code, resulting in Remote Code Execution. This issue affects Pandora FMS: from 777 onwards.
Published: 2026-10-01
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A chained CSRF bypass combined with an unrestricted file upload flaw in the File Manager plugin enables an attacker to upload and run arbitrary PHP code. This results in full remote code execution, compromising confidentiality, integrity, and availability of the affected system. The vulnerability stems from missing CSRF protection and inadequate file type validation, as reflected by the CWE-352 and CWE-434 identifiers.

Affected Systems

The flaw impacts Pandora FMS installations from version 777 onward, specifically when the File Manager plugin is enabled. The vulnerability is limited to this plugin and does not affect other components of Pandora FMS.

Risk and Exploitability

The CVSS score of 7.5 classifies the issue as high severity, and the lack of an EPSS score indicates no available exploitation probability data; however, since the vulnerability is accessible via web requests, the attack vector is likely remote. The attack does not require privileged access, and the impact is severe, granting full code execution on the affected server. The vulnerability is not currently listed in the CISA KEV catalog, but its potential for widespread compromise warrants prompt action.

Generated by OpenCVE AI on October 1, 2026 at 11:00 UTC.

Remediation

Vendor Solution

Fixed v800.5 and v805


OpenCVE Recommended Actions

  • Apply the vendor patch available in version 800.5 or 805 to resolve the CSRF and file‑type validation issues.
  • Disable the File Manager plugin until the patch is applied, preventing any file upload activity via the plugin.
  • Configure the web application to enforce strict file type restrictions for uploads, allowing only approved extensions and sanitizing filenames.

Generated by OpenCVE AI on October 1, 2026 at 11:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Pandora Fms
Pandora Fms pandora Fms
Vendors & Products Pandora Fms
Pandora Fms pandora Fms

Thu, 01 Oct 2026 09:45:00 +0000

Type Values Removed Values Added
Description A chained CSRF bypass and unrestricted file upload vulnerability in the Plugin File Manager allows an attacker to upload and execute arbitrary PHP code, resulting in Remote Code Execution. This issue affects Pandora FMS: from 777 onwards.
Title CSRF Bypass Leading to Remote Code Execution via Unrestricted File Upload in Plugin File Manager
Weaknesses CWE-352
CWE-434
References
Metrics cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/S:N/AU:Y/R:I/V:C/RE:H/U:Red'}


Subscriptions

Pandora Fms Pandora Fms
cve-icon MITRE

Status: PUBLISHED

Assigner: PandoraFMS

Published:

Updated: 2026-10-01T19:24:10.100Z

Reserved: 2026-07-21T06:52:17.076Z

Link: CVE-2026-64947

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T10:17:15.917

Modified: 2026-10-01T12:45:05.900

Link: CVE-2026-64947

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T11:00:06Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-434

    Unrestricted Upload of File with Dangerous Type