Executive brief
Pandora FMS, a monitoring and management platform, contains a security vulnerability in its configuration interface. An authenticated user with low-level access can bypass authorization checks to view sensitive system information. This could lead to the exposure of internal configuration details that should be restricted to administrators.
Technical details
A Missing Authorization vulnerability (CWE-276/CWE-862) exists in Pandora FMS versions 777 through 800. The flaw is located within a configuration endpoint that fails to properly validate user permissions before displaying data. An attacker with a low-privileged account can access this endpoint over the network to retrieve sensitive configuration information. The vulnerability has been addressed in version 800.1. CVSS 3.1 scoring indicates a base score of 6.5, primarily impacting confidentiality.
Affected products
- Artica PFMS Pandora FMS 777 through 800
Timeline
- 2026-04-13: disclosed: Initial disclosure by Artica PFMS
- 2026-04-13: advisory: NVD published date
- 2026-04-22: other: NVD analysis and enrichment completed