CVE-2026-64949

Status: Received

Description

Incomplete extension blacklist in the File Manager module allows authenticated upload and execution of arbitrary .phar files. Affects Pandora FMS from 777 onwards.

Published
October 1, 2026 10:17 AM
Last Modified
October 1, 2026 10:17 AM
Source
[email protected]

Weaknesses (CWE)

CWE-434

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.