CVE-2026-34189
Received Received - Intake

Cross-Site Request Forgery in Pandora FMS Allows Event Response Deletion

Vulnerability report for CVE-2026-34189, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Artica PFMS

Description

Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of event responses via a forged GET request when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pandora_fms pandora_fms From 777 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Cross-Site Request Forgery (CSRF) vulnerability in Pandora FMS versions 777 and later. It allows an attacker to trick an authenticated administrator into visiting a malicious page, which then sends a forged GET request to delete event responses without proper authorization.

Detection Guidance

Detecting this CSRF vulnerability requires checking for unauthorized event response deletions in Pandora FMS logs. Look for GET requests to event deletion endpoints from authenticated administrators. Review server access logs for suspicious GET requests targeting event management URLs.

Impact Analysis

An attacker could exploit this to delete important event responses in your Pandora FMS system, potentially disrupting monitoring and management of your infrastructure. This could lead to loss of critical data or operational issues if responses are unintentionally removed.

Compliance Impact

This CSRF vulnerability could potentially allow unauthorized actions (deletion of event responses) by tricking an authenticated administrator into visiting a malicious page. This may impact compliance by violating data integrity and access control requirements in standards like GDPR (Article 32) and HIPAA (Safeguard requirements), as unauthorized modifications or deletions of data could occur without proper authorization.

Mitigation Strategies

Immediately upgrade Pandora FMS to a version prior to 777. Disable GET requests for sensitive operations like event deletions. Implement CSRF tokens for all state-changing requests. Restrict administrative access to trusted networks only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-34189. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart