CVE-2026-30808: Session Fixation in Authentication leads to Session Hijacking
Published May 12, 2026
·Updated
Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue affects Pandora FMS: from 777 through 800
Affected Software
3 affected components
Pandora FMS Pandora FMS>=777<=800
Artica Pandora FMS<777.17
Artica Pandora FMS>=778<802
Remediation
Information
Fixed in v802 and 800.2
Event History
May 12, 2026
CVE Published
via MITRE·03:11 PM
Data Sourced
via MITRE·03:11 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-30808?
CVE-2026-30808 is considered a critical vulnerability due to its potential to lead to session hijacking.
2
How do I fix CVE-2026-30808?
To fix CVE-2026-30808, ensure you are using the latest version of Pandora FMS that is patched against this vulnerability.
3
Which versions of Pandora FMS are affected by CVE-2026-30808?
CVE-2026-30808 affects Pandora FMS versions 777 through 800.
4
What type of attack is associated with CVE-2026-30808?
CVE-2026-30808 is associated with a session fixation attack that can lead to session hijacking.
5
What can happen if CVE-2026-30808 is exploited?
If exploited, CVE-2026-30808 can allow an attacker to hijack user sessions, gaining unauthorized access to user information.