Description
Missing authorization in module data retrieval allows unauthorized cross-group access to module history. Affects Pandora FMS from 777 onwards.
Published: 2026-10-01
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Cross‑group module data disclosure
Action: Apply Patch
AI Analysis

Impact

A missing authorization check in the get_module_detail AJAX endpoint allows a user to retrieve module history from any group to which they have no access. This can expose sensitive operational data and configuration settings across organizational boundaries. The flaw is a pure confidentiality violation, not an integrity or availability concern.

Affected Systems

Pandora FMS software, versions 777 and newer. The vulnerability applies to all releases of Pandora FMS that contain the get_module_detail endpoint, including the 800.5 and 804 builds that contain the fix.

Risk and Exploitability

The CVSS score is 7.1, indicating a high severity. Since the EPSS score is not available, the current probability of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely via the Web interface, relying on user credentials or session tokens to bypass group boundaries. No special conditions or elevated privileges are required beyond access to the Web UI.

Generated by OpenCVE AI on October 1, 2026 at 10:32 UTC.

Remediation

Vendor Solution

Fixed v800.5 and v804


OpenCVE Recommended Actions

  • Upgrade Pandora FMS to a version that includes v800.5 or v804, which contain the authorization fix for get_module_detail.
  • Re‑validate that the get_module_detail endpoint now enforces group‑based access control by attempting to access it with a non‑admin account.
  • Review and tighten group membership and audit logs to detect any unauthorized cross‑group access attempts.

Generated by OpenCVE AI on October 1, 2026 at 10:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Pandora Fms
Pandora Fms pandora Fms
Vendors & Products Pandora Fms
Pandora Fms pandora Fms

Thu, 01 Oct 2026 09:45:00 +0000

Type Values Removed Values Added
Description Missing authorization in module data retrieval allows unauthorized cross-group access to module history. Affects Pandora FMS from 777 onwards.
Title Missing Authorization in get_module_detail AJAX Endpoint Allows Cross-Group Module Data Disclosure
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/S:N/AU:Y/R:A/V:C/RE:L/U:Amber'}


Subscriptions

Pandora Fms Pandora Fms
cve-icon MITRE

Status: PUBLISHED

Assigner: PandoraFMS

Published:

Updated: 2026-10-01T09:28:33.626Z

Reserved: 2026-07-21T06:52:17.076Z

Link: CVE-2026-64948

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T10:17:16.057

Modified: 2026-10-01T12:45:05.900

Link: CVE-2026-64948

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T14:45:09Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key