CVE-2024-11320: Pandorafms Pandora Fms

Critical severity, CVSS 9.8. EPSS: 91.2% chance of exploitation in the next 30 days.

Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pandora FMS: from 700 through <=777.4

Affected products

  • Pandorafms Pandora Fms: from 700, before 777.5 (fixed in 777.5)

Published 2024-11-21. Last modified 2026-06-17.