CVE-2026-30811: Missing Authorization in Configuration Ajax Endpoint leads to Information Disclosure
Published Apr 13, 2026
·Updated
Missing Authorization vulnerability allows Exposure of Sensitive Information via configuration endpoint. This issue affects Pandora FMS: from 777 through 800
Affected Software
2 affected components
Pandora FMS Pandora FMS>=777<=800
Artica Pandora FMS>=777<800.1
Remediation
Information
Fixed in v800.1 and v801 Pandora FMS versions
Event History
Apr 13, 2026
CVE Published
via MITRE·03:47 PM
Data Sourced
via MITRE·03:47 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-30811?
CVE-2026-30811 is considered a high severity vulnerability due to the potential for sensitive information exposure.
2
How do I fix CVE-2026-30811?
To fix CVE-2026-30811, ensure that proper authorization controls are implemented on the configuration Ajax endpoint.
3
What software versions are affected by CVE-2026-30811?
CVE-2026-30811 affects Pandora FMS versions between 777 and 800.
4
What type of vulnerability is CVE-2026-30811?
CVE-2026-30811 is classified as a Missing Authorization vulnerability.
5
What are the consequences of CVE-2026-30811?
CVE-2026-30811 may lead to the unauthorized exposure of sensitive information.