CVE-2026-64950

Status: Received

Description

Missing input validation and output encoding on the directory name parameter in File Manager's Create Directory allows stored XSS, executing without user interaction. Affects Pandora FMS from 777 onwards.

Published
October 1, 2026 10:17 AM
Last Modified
October 1, 2026 10:17 AM
Source
[email protected]

Weaknesses (CWE)

CWE-79

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.