Junglewise Threat Intelligence

CVE-2026-34188: Artica Pandora FMS OS command injection in Event Response

CVE-2026-34188 · Severity: high · CVSS 7.2 · Published 2026-04-13

Technologies: Artica PFMS Pandora Fms. Vendors: Artica.

Executive brief

A security vulnerability has been identified in Pandora FMS, a monitoring platform used to oversee IT infrastructure and networks. An attacker with high-level administrative privileges can execute unauthorized operating system commands through the Event Response feature. This could lead to a complete takeover of the monitoring server, potentially resulting in data theft, service disruption, or further attacks on the internal network.

Technical details

An OS Command Injection vulnerability (CWE-78) exists in Artica Pandora FMS versions 777 through 800. The flaw is located in the Event Response execution component, where the application fails to properly neutralize special elements used in OS commands. An attacker with high privileges (PR:H) can exploit this over the network without user interaction to execute arbitrary commands on the underlying operating system. This can lead to full compromise of the host's confidentiality, integrity, and availability. The vulnerability is addressed in version 800.1.

Affected products

  • Artica PFMS Pandora FMS 777 through 800

Timeline

  • 2026-04-13: disclosed
  • 2026-04-13: advisory
  • 2026-04-22: patched: NIST analysis indicates fix in version 800.1

References

Related threats