Description
Incomplete extension blacklist in the File Manager module allows authenticated upload and execution of arbitrary .phar files. Affects Pandora FMS from 777 onwards.
Published: 2026-10-01
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the File Manager module of Pandora FMS. An incomplete extension blacklist permits an authenticated user to upload .phar files, which the system then executes. This flaw enables an attacker to run arbitrary code on the server, giving full control over the affected system. The weakness corresponds to CWE‑434: Unrestricted Upload of File with Dangerous Type.

Affected Systems

Pandora FMS versions 777 and later are impacted. The flaw is present in all releases from 777 up to the patched releases v800.5 and v805.

Risk and Exploitability

The vulnerability has a CVSS score of 8.6, indicating high severity. EPSS data is unavailable, and the issue is not currently listed in CISA KEV. Attacking requires valid authentication to the admin interface, after which an attacker can upload a malicious .phar and trigger execution. Because the flaw allows arbitrary code execution with elevated privileges, it poses a severe risk to confidentiality, integrity, and availability of the affected systems.

Generated by OpenCVE AI on October 1, 2026 at 10:32 UTC.

Remediation

Vendor Solution

Fixed v800.5 and v805


OpenCVE Recommended Actions

  • Upgrade to a patched release (v800.5 or v805).
  • If upgrading is delayed, disable or block .phar uploads and enforce a strict whitelist of allowed file types on the File Manager component.
  • Restrict file upload permissions to only necessary administrative accounts and monitor upload activity.

Generated by OpenCVE AI on October 1, 2026 at 10:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Pandora Fms
Pandora Fms pandora Fms
Vendors & Products Pandora Fms
Pandora Fms pandora Fms

Thu, 01 Oct 2026 09:45:00 +0000

Type Values Removed Values Added
Description Incomplete extension blacklist in the File Manager module allows authenticated upload and execution of arbitrary .phar files. Affects Pandora FMS from 777 onwards.
Title Unrestricted File Upload Leading to Remote Code Execution in Admin Tools File Manager
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/S:N/AU:Y/R:I/V:C/RE:M/U:Red'}


Subscriptions

Pandora Fms Pandora Fms
cve-icon MITRE

Status: PUBLISHED

Assigner: PandoraFMS

Published:

Updated: 2026-10-01T19:12:33.964Z

Reserved: 2026-07-21T06:52:17.077Z

Link: CVE-2026-64949

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T10:17:16.207

Modified: 2026-10-01T12:45:05.900

Link: CVE-2026-64949

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T10:45:07Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type