OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-64946

HIGH · CVSS 7.4 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The File Manager module in Pandora FMS versions 777 and later is vulnerable to a chained CSRF and unrestricted SVG file upload flaw, which can lead to stored Cross-Site Scripting (XSS). This vulnerability allows attackers to exfiltrate session cookies and potentially take over administrator accounts. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access and data breaches.

CVE
CVE-2026-64946
Severity
HIGH
CVSS
7.4
EPSS
0.16%

Original NVD Description

A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account takeover. This issue affects Pandora FMS: from 777 onwards.