Junglewise Threat Intelligence

CVE-2026-30808: Artica Pandora FMS session fixation

CVE-2026-30808 · Severity: high · CVSS 8.1 · Published 2026-05-12

Technologies: Artica PFMS Pandora Fms.

Executive brief

A security vulnerability has been identified in Pandora FMS, a monitoring platform used to oversee IT infrastructure and networks. An attacker can trick a user into using a specific session ID, allowing the attacker to hijack the user's session once they log in. This could lead to unauthorized access to the monitoring dashboard, potentially exposing sensitive infrastructure data or allowing the attacker to modify system configurations.

Technical details

A session fixation vulnerability (CWE-384) exists in Pandora FMS versions 777 through 800. The application fails to invalidate or renew the session ID upon user authentication, allowing an attacker to provide a crafted session ID to a victim. If the victim subsequently authenticates using that ID, the attacker can hijack the active session. This attack typically requires some user interaction (e.g., clicking a link containing the pre-set session ID) but does not require prior authentication by the attacker. Successful exploitation grants the attacker the same privileges as the hijacked user. The issue is addressed in versions 777.17 and 802.

Affected products

  • Artica PFMS Pandora FMS 777 through 800

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References