CVE-2026-64949
Received Received - Intake

Incomplete Extension Blacklist in Pandora FMS File Manager Allows Arbitrary PHAR Execution

Vulnerability report for CVE-2026-64949, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Artica PFMS

Description

Incomplete extension blacklist in the File Manager module allows authenticated upload and execution of arbitrary .phar files. Affects Pandora FMS from 777 onwards.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pandora_fms pandora_fms From 777 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Pandora FMS File Manager module. It allows authenticated users to upload and execute arbitrary .phar files due to an incomplete extension blacklist. This affects versions from 777 onwards.

Detection Guidance

Check for unauthorized .phar files in the File Manager module of Pandora FMS versions 777 and above. Review uploaded files and execution logs for suspicious .phar extensions.

Impact Analysis

An attacker with access could upload malicious .phar files to execute arbitrary code on the server. This could lead to full system compromise, data theft, or further network infiltration depending on the system's configuration.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR (data protection) and HIPAA (health data privacy). Organizations may face fines, legal action, and reputational damage if exploited.

Mitigation Strategies

Disable the File Manager module in Pandora FMS if not required. Ensure all uploaded files are scanned for malicious content. Restrict file upload permissions to trusted users only. Update to the latest version of Pandora FMS if an update addressing this issue is available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-64949. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart