CyberRota Analysis
AI-GeneratedThe File Manager module in Pandora FMS versions 777 and later has an incomplete extension blacklist that permits authenticated users to upload and execute arbitrary .phar files, potentially leading to remote code execution. Organizations using affected versions should prioritize remediation to mitigate the risk of unauthorized access and exploitation. Immediate action is recommended for environments where file uploads are permitted, particularly in sensitive or critical infrastructure settings.
CVE
CVE-2026-64949
Severity
HIGH
CVSS
8.6
EPSS
0.30%
Original NVD Description
Incomplete extension blacklist in the File Manager module allows authenticated upload and execution of arbitrary .phar files. Affects Pandora FMS from 777 onwards.