CVE-2026-64946: Pandora Fms
High severity, CVSS 7.4. EPSS: 0.2% chance of exploitation in the next 30 days.
A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account takeover. This issue affects Pandora FMS: from 777 onwards.
Affected products
- Pandora Fms Pandora Fms: version 777 only
Published 2026-10-01. Last modified 2026-10-01.