Junglewise Threat Intelligence

CVE-2026-30809: Artica Pandora FMS OS command injection in WebServerModuleDebug

CVE-2026-30809 · Severity: high · CVSS 8.8 · Published 2026-04-13

Technologies: Artica PFMS Pandora Fms. Vendors: Artica.

Executive brief

Pandora FMS, a monitoring and IT management platform, contains a vulnerability that could allow an attacker to execute unauthorized commands on the underlying operating system. By exploiting a specific debugging module, a logged-in user with low privileges could potentially take full control of the server, leading to data theft or service disruption. This issue affects versions 777 through 800 of the software.

Technical details

An OS Command Injection vulnerability (CWE-78) exists in Pandora FMS within the WebServerModuleDebug component. The flaw stems from improper neutralization of special elements used in an OS command, allowing an attacker to inject and execute arbitrary system commands. The attack vector is network-based and requires low-privileged (PR:L) authentication. Successful exploitation grants the attacker the ability to execute code with the privileges of the web server user, potentially leading to full system compromise. The vulnerability is present in versions 777 through 800; version 800.1 is reported as a potential fix version in CPE configurations.

Affected products

  • Artica PFMS Pandora FMS 777 through 800

Timeline

  • 2026-04-13: disclosed: CVE published by Artica PFMS
  • 2026-04-13: advisory: Vendor advisory published
  • 2026-04-22: other: NIST initial analysis and CPE enrichment

References

Related threats