Junglewise Threat Intelligence

CVE-2026-30810: Artica Pandora FMS SSRF and privilege escalation in API Checker extension

CVE-2026-30810 · Severity: high · CVSS 8.8 · Published 2026-05-12

Technologies: Artica PFMS Pandora Fms.

Executive brief

Pandora FMS, a comprehensive IT monitoring and management platform, contains a security vulnerability in its API Checker extension. An attacker with basic user access can trick the server into making unauthorized requests to internal systems, potentially leading to an escalation of privileges. This could allow an unauthorized user to gain higher-level administrative control over the monitoring environment and its data.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists within the API Checker extension of Pandora FMS versions 777 through 800. The flaw allows an authenticated attacker with low-level privileges (PR:L) to send crafted requests through the server, which can be leveraged to achieve privilege escalation. By exploiting this SSRF, the attacker can interact with internal services or the application's own API in a way that bypasses intended access controls. The vulnerability has a CVSS 3.1 base score of 8.8, reflecting high impact on confidentiality, integrity, and availability. Users should update to a version outside the 777-800 range (e.g., 802 or later as indicated by CPE data) to mitigate this risk.

Affected products

  • Artica PFMS Pandora FMS 777 through 800

Timeline

  • 2026-05-12: disclosed: Initial disclosure by Artica PFMS
  • 2026-05-12: advisory: NVD publication date

References