CyberRota Analysis
AI-GeneratedAuthenticated users of Pandora FMS versions 777 and above are vulnerable to a blind SQL injection due to unsanitized concatenation of module parameters in the Grafana datasource endpoint. This vulnerability could allow attackers to execute arbitrary SQL queries, potentially leading to unauthorized data access or manipulation. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation.
CVE
CVE-2026-75786
Severity
HIGH
CVSS
7.2
EPSS
0.20%
Original NVD Description
Unsanitized concatenation of the module parameter in the Grafana datasource endpoint allows authenticated blind SQL injection. Affects Pandora FMS from 777 onwards.