Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Fixed v800.5 and v805
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pandora Fms
Pandora Fms pandora Fms |
|
| Vendors & Products |
Pandora Fms
Pandora Fms pandora Fms |
Thu, 01 Oct 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incomplete extension blacklist in the File Manager module allows authenticated upload and execution of arbitrary .phar files. Affects Pandora FMS from 777 onwards. | |
| Title | Unrestricted File Upload Leading to Remote Code Execution in Admin Tools File Manager | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: PandoraFMS
Published:
Updated: 2026-10-01T09:29:30.649Z
Reserved: 2026-07-21T06:52:17.077Z
Link: CVE-2026-64949
No data.
Status : Deferred
Published: 2026-10-01T10:17:16.207
Modified: 2026-10-01T12:45:05.900
Link: CVE-2026-64949
No data.
OpenCVE Enrichment
Updated: 2026-10-01T10:45:07Z
-
CWE-434
Unrestricted Upload of File with Dangerous Type