CVE-2026-34190
Received Received - Intake

Cross-Site Request Forgery in Pandora FMS Allows Alert Deletion

Vulnerability report for CVE-2026-34190, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Artica PFMS

Description

Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of alert commands via sequential, unvalidated GET requests when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pandora_fms pandora_fms From 777 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Cross-Site Request Forgery (CSRF) vulnerability in Pandora FMS versions 777 and later. It allows unauthorized deletion of alert commands when an authenticated administrator visits a malicious page. The vulnerability occurs because GET requests are used for sensitive actions without proper validation.

Detection Guidance

Detecting this CSRF vulnerability requires checking for unauthorized deletion of alert commands via GET requests. Monitor web server logs for repeated GET requests targeting alert deletion endpoints from administrator sessions. Look for unusual sequential requests or patterns indicating malicious activity.

Impact Analysis

An attacker could trick an administrator into visiting a malicious page, leading to unauthorized deletion of alert commands. This could disrupt monitoring and alerting systems, potentially causing missed critical events or system failures.

Compliance Impact

This CSRF vulnerability could potentially impact compliance with GDPR and HIPAA by enabling unauthorized actions (deletion of alert commands) through malicious requests. Unauthorized changes to systems handling sensitive data may violate integrity and access control requirements under these regulations.

Mitigation Strategies

Immediately upgrade Pandora FMS to a patched version. Disable GET requests for sensitive actions like alert deletion and enforce POST requests with CSRF tokens. Review administrator session logs for signs of exploitation and revoke any unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-34190. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart