Executive brief
A vulnerability in Pandora FMS, a popular IT infrastructure monitoring solution, allows attackers to perform SQL injection through custom fields. An attacker with low-level user privileges could exploit this to gain unauthorized access to the underlying database, potentially leading to the theft of sensitive monitoring data, modification of system configurations, or a complete takeover of the monitoring platform. This could significantly impact an organization's ability to maintain visibility and security over their IT operations.
Technical details
An SQL injection vulnerability exists in Pandora FMS versions 777 through 800 due to improper neutralization of special elements used in SQL commands within custom fields. The vulnerability (CWE-89) can be exploited by a remote attacker with low-level authenticated privileges (PR:L) to inject malicious SQL queries. Successful exploitation allows the attacker to read, modify, or delete sensitive data within the database, and potentially achieve full administrative control over the application. The issue is addressed in version 800.1 and later.
Affected products
- Artica PFMS Pandora FMS 777 through 800
Timeline
- 2026-04-13: disclosed: Initial disclosure by Artica PFMS
- 2026-04-13: advisory: CVE-2026-34186 published
- 2026-04-22: other: NIST analysis and CPE enrichment completed