OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-64949

HIGH · CVSS 8.6 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The File Manager module in Pandora FMS versions 777 and later has an incomplete extension blacklist that permits authenticated users to upload and execute arbitrary .phar files, potentially leading to remote code execution. Organizations using affected versions should prioritize remediation to mitigate the risk of unauthorized access and exploitation. Immediate action is recommended for environments where file uploads are permitted, particularly in sensitive or critical infrastructure settings.

CVE
CVE-2026-64949
Severity
HIGH
CVSS
8.6
EPSS
0.30%

Original NVD Description

Incomplete extension blacklist in the File Manager module allows authenticated upload and execution of arbitrary .phar files. Affects Pandora FMS from 777 onwards.