Back

HIGH

CSRF Bypass Leading to Remote Code Execution via Unrestricted File Upload in Plugin File Manager

Published Oct 1, 2026

Description

A chained CSRF bypass and unrestricted file upload vulnerability in the Plugin File Manager allows an attacker to upload and execute arbitrary PHP code, resulting in Remote Code Execution. This issue affects Pandora FMS: from 777 onwards.

Affected products

Remediation

Vendor solution

Fixed v800.5 and v805

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner PandoraFMS
Published Oct 1, 2026
Updated Oct 1, 2026
Reserved Jul 21, 2026
CISA Vulnrichment
Updated Oct 1, 2026
NVD
Status Received
Modified Oct 1, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner PandoraFMS
Published Oct 1, 2026
Updated Oct 1, 2026
Exploited since n/a
EUVD-2026-90596