Executive brief
A security vulnerability has been identified in Pandora FMS, a monitoring platform used to oversee IT infrastructure and networks. An attacker with basic user access can exploit the module search feature to run unauthorized database commands. This could lead to the theft of sensitive monitoring data, modification of system configurations, or a complete takeover of the monitoring server.
Technical details
An SQL injection vulnerability (CWE-89) exists in Pandora FMS versions 777 through 800 due to improper neutralization of special elements in the module search component. The flaw allows a remote attacker with low-level privileges (PR:L) to inject malicious SQL queries through the search interface. Successful exploitation can lead to unauthorized access to the underlying database, enabling the attacker to read, modify, or delete sensitive information, and potentially escalate privileges within the application. The vulnerability is addressed in version 800.1.
Affected products
- Artica PFMS Pandora FMS 777 through 800
Timeline
- 2026-04-13: disclosed: Initial disclosure by Artica PFMS
- 2026-04-13: advisory: NVD publication date
- 2026-04-22: other: NVD analysis and CPE assignment completed