Junglewise Threat Intelligence

CVE-2026-30812: Artica Pandora FMS Stored XSS in event comments

CVE-2026-30812 · Severity: medium · CVSS 5.4 · Published 2026-04-13

Technologies: Artica PFMS Pandora Fms. Vendors: Artica.

Executive brief

Pandora FMS, a monitoring and IT management platform, is vulnerable to a security flaw where malicious scripts can be embedded in event comments. If an authorized user views these comments, the scripts could execute in their browser, potentially allowing an attacker to perform actions on their behalf or access sensitive session information. This affects versions 777 through 800.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in Pandora FMS due to improper neutralization of user-supplied input during web page generation (CWE-79). The vulnerability is located in the event comments component. An authenticated attacker with low privileges can inject malicious JavaScript into the comment field. When other users, including administrators, view the affected event, the script executes in the context of their browser session. This can lead to session hijacking, unauthorized configuration changes, or further privilege escalation. The issue affects versions 777 through 800; users should update to version 800.1 or later.

Affected products

  • Artica PFMS Pandora FMS 777 through 800

Timeline

  • 2026-04-13: disclosed
  • 2026-04-13: advisory
  • 2026-04-22: patched: NIST analysis indicates fix in version 800.1

References

Related threats