CVE-2026-64947
Received
Received - Intake
CSRF Bypass and File Upload RCE in Pandora FMS
Vulnerability report for CVE-2026-64947, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-01
Last updated on: 2026-10-01
Assigner: Artica PFMS
Description
Description
A chained CSRF bypass and unrestricted file upload vulnerability in the Plugin File Manager allows an attacker to upload and execute arbitrary PHP code, resulting in Remote Code Execution. This issue affects Pandora FMS: from 777 onwards.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| pandora_fms | file_manager | From 777 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-434 | The product allows the upload or transfer of dangerous file types that are automatically processed within its environment. |
| CWE-352 | The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor. |