CVE-2026-30807: Cross-Site Request Forgery on Extension Pages
Published May 12, 2026
·Updated
Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This issue affects Pandora FMS: from 777 through 800
Affected Software
3 affected components
Pandora FMS Pandora FMS>=777<=800
Artica Pandora FMS<777.17
Artica Pandora FMS>=778<802
Remediation
Information
Fixed in v802 and v800.2
Event History
May 12, 2026
CVE Published
via MITRE·03:11 PM
Data Sourced
via MITRE·03:11 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-30807?
The severity of CVE-2026-30807 is considered high due to the potential for unauthorized actions via Cross-Site Request Forgery.
2
How do I fix CVE-2026-30807?
To fix CVE-2026-30807, update Pandora FMS to a version later than 800 or apply recommended security patches.
3
What versions of Pandora FMS are affected by CVE-2026-30807?
CVE-2026-30807 affects Pandora FMS versions from 777 to 800.
4
What is a Cross-Site Request Forgery in the context of CVE-2026-30807?
In the context of CVE-2026-30807, Cross-Site Request Forgery allows attackers to perform actions on behalf of authenticated users without their consent.
5
Are there any known exploits for CVE-2026-30807?
Yes, there are known exploits for CVE-2026-30807 that can be used to perform unauthorized actions on vulnerable systems.