OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-75786

HIGH · CVSS 7.2 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Authenticated users of Pandora FMS versions 777 and above are vulnerable to a blind SQL injection due to unsanitized concatenation of module parameters in the Grafana datasource endpoint. This vulnerability could allow attackers to execute arbitrary SQL queries, potentially leading to unauthorized data access or manipulation. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-75786
Severity
HIGH
CVSS
7.2
EPSS
0.20%

Original NVD Description

Unsanitized concatenation of the module parameter in the Grafana datasource endpoint allows authenticated blind SQL injection. Affects Pandora FMS from 777 onwards.