CVE-2026-64949

Summary

Incomplete extension blacklist in the File Manager module allows authenticated upload and execution of arbitrary .phar files. Affects Pandora FMS from 777 onwards.

Affected Software

VendorProductVersion RangeStatus
Pandora FMSPandora FMS777affected

Weaknesses

  • CWE-434: CWE-434 Unrestricted upload of file with dangerous type

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References