Executive brief
Pandora FMS, a popular IT monitoring and management platform, contains a security vulnerability that allows an attacker to upload malicious files. If exploited, this could allow an attacker to take full control of the monitoring server and execute arbitrary commands. This could lead to significant operational disruption, unauthorized access to sensitive monitoring data, and a foothold for further attacks within the corporate network.
Technical details
An unrestricted file upload vulnerability (CWE-434) exists in Pandora FMS versions 777 through 800. The flaw allows an authenticated user with high privileges (PR:H) to upload files with dangerous extensions to the server. Because the application fails to properly validate or sanitize these uploads, an attacker can upload a web shell or malicious script and execute it remotely on the underlying operating system. This results in full Remote Code Execution (RCE) with the permissions of the web server user. The vulnerability is reachable over the network without user interaction. Users should upgrade to version 800.1 or later to remediate the issue.
Affected products
- Artica PFMS Pandora FMS 777 through 800
Timeline
- 2026-04-13: disclosed: Initial disclosure by Artica PFMS
- 2026-04-13: advisory: NVD published date