CVE-2026-30805: Insecure Default Initialization in API Authentication leads to Authentication Bypass
Published May 12, 2026
·Updated
Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affects Pandora FMS: from 777 through 800
Affected Software
3 affected components
Pandora FMS Pandora FMS>=777<=800
Artica Pandora FMS<777.17
Artica Pandora FMS>=778<802
Remediation
Information
Fixed in v802 and 800.2
Event History
May 12, 2026
CVE Published
via MITRE·03:09 PM
Data Sourced
via MITRE·03:09 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-30805?
The severity of CVE-2026-30805 is considered high due to the potential for authentication bypass.
2
How do I fix CVE-2026-30805?
To fix CVE-2026-30805, ensure that secure initialization procedures are in place for API authentication.
3
What versions of Pandora FMS are affected by CVE-2026-30805?
CVE-2026-30805 affects Pandora FMS versions from 777 through 800.
4
Can CVE-2026-30805 lead to data breaches?
Yes, CVE-2026-30805 can potentially lead to unauthorized access and data breaches due to authentication bypass.
5
Is a patch available for CVE-2026-30805?
Users should check for the latest updates from Pandora FMS to address the vulnerabilities identified in CVE-2026-30805.