Junglewise Threat Intelligence

CVE-2026-30805: Artica Pandora FMS authentication bypass in API

CVE-2026-30805 · Severity: critical · CVSS 9.1 · Published 2026-05-12

Technologies: Artica PFMS Pandora Fms.

Executive brief

Pandora FMS, a monitoring platform used to oversee corporate IT infrastructure and networks, contains a security flaw in its API. This vulnerability allows an attacker to bypass authentication and gain unauthorized access to the system. An exploit could lead to the exposure of sensitive monitoring data or unauthorized changes to the IT management environment.

Technical details

An Insecure Default Initialization of Resource vulnerability (CWE-1188) exists in Pandora FMS versions 777 through 800. The flaw resides in the API component, where improper initialization allows an attacker to bypass authentication mechanisms. This is a network-based attack that does not require prior privileges or user interaction, though some environmental conditions may affect exploitability (reflected in the High Access Complexity/Technical Parameter in CVSS 4.0). Successful exploitation allows an attacker to perform unauthorized actions via the API, potentially leading to full compromise of the monitoring data and system configuration. Artica PFMS has addressed this in newer versions (e.g., 802).

Affected products

  • Artica PFMS Pandora FMS 777 through 800

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Original advisory published by Artica PFMS

References