Junglewise Threat Intelligence

CVE-2026-30807: Artica Pandora FMS Cross-Site Request Forgery

CVE-2026-30807 · Severity: high · CVSS 8.8 · Published 2026-05-12

Technologies: Artica PFMS Pandora Fms. Vendors: Artica.

Executive brief

A security vulnerability exists in Pandora FMS, a monitoring platform used to oversee IT infrastructure and networks. An attacker could trick a logged-in administrator into visiting a malicious website, which then silently performs unauthorized actions within the monitoring console. This could lead to unauthorized configuration changes, data theft, or a complete takeover of the monitoring system.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability (CWE-352) exists in Artica Pandora FMS versions 777 through 800. The application fails to properly validate requests, allowing an attacker to execute state-changing operations by tricking an authenticated user into interacting with a malicious link or website. Successful exploitation requires user interaction from an authenticated victim but can result in full compromise of the application's integrity and confidentiality. The vulnerability is addressed in versions starting from 802 (and specifically patched in 777.17 for that branch).

Affected products

  • Artica PFMS Pandora FMS 777 through 800

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats