CVE-2023-2807: Pandorafms Pandora Fms

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a password reset process for any user account without proper authentication. This issue affects PandoraFMS v771 and prior versions on all platforms.

Affected products

Published 2023-06-13. Last modified 2026-06-17.