High severityNVD Advisory· Published Oct 1, 2026
CVE-2026-64947
CVE-2026-64947
Description
A chained CSRF bypass and unrestricted file upload vulnerability in the Plugin File Manager allows an attacker to upload and execute arbitrary PHP code, resulting in Remote Code Execution. This issue affects Pandora FMS: from 777 onwards.
Affected products
2- Range: >=777
- Range: >=777
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.