CVE-2026-30810: Server-Side Request Forgery in API Checker leads to Privilege Escalation
Published May 12, 2026
·Updated
Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pandora FMS: from 777 through 800
Affected Software
3 affected components
Pandora FMS Pandora FMS>=777<=800
Artica Pandora FMS<777.17
Artica Pandora FMS>=778<802
Remediation
Information
Fixed in v802 and v800.2
Event History
May 12, 2026
CVE Published
via MITRE·03:12 PM
Data Sourced
via MITRE·03:12 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-30810?
CVE-2026-30810 is considered a high-severity vulnerability due to its potential for privilege escalation through Server-Side Request Forgery.
2
How do I fix CVE-2026-30810?
To fix CVE-2026-30810, upgrade the Pandora FMS to version 801 or higher to address the vulnerability.
3
Which versions of Pandora FMS are affected by CVE-2026-30810?
CVE-2026-30810 affects Pandora FMS versions 777 through 800.
4
What type of vulnerability is CVE-2026-30810?
CVE-2026-30810 is a Server-Side Request Forgery (SSRF) vulnerability.
5
What impact does CVE-2026-30810 have?
CVE-2026-30810 can lead to privilege escalation, allowing attackers to gain unauthorized access to sensitive information.