CVE-2020-26518: Artica Pandora Fms

Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.

Artica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandora_console/include/chart_generator.php session_id parameter.

Affected products

  • Artica Pandora Fms: before 743 (fixed in 743)

Published 2020-10-02. Last modified 2026-06-17.