Executive brief
Pandora FMS, a monitoring platform used to oversee IT infrastructure and networks, is vulnerable to a security flaw in its graphing component. An attacker with low-level user access can exploit this to run unauthorized database commands. This could lead to the theft of sensitive monitoring data or the modification of system records, potentially compromising the integrity of the entire monitoring environment.
Technical details
An SQL injection vulnerability exists in Pandora FMS versions 777 through 800 due to improper neutralization of special elements within the 'graph container' parameter. The flaw allows an authenticated attacker with low privileges (PR:L) to inject malicious SQL commands into database queries. While the attack requires specific conditions (AC:H, AT:P), a successful exploit can lead to high confidentiality and integrity impacts on the underlying database. The vulnerability is tracked as CVE-2026-34187 and was disclosed by Artica PFMS.
Affected products
- Artica PFMS Pandora FMS 777 through 800
Timeline
- 2026-05-12: disclosed: Initial disclosure by Artica PFMS and NVD publication.