CVE-2026-34187: SQL Injection in Graph Container Parameter
Published May 12, 2026
·Updated
Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph container parameter. This issue affects Pandora FMS: from 777 through 800
Affected Software
3 affected components
Pandora FMS Pandora FMS>=777<=800
Artica Pandora FMS<777.17
Artica Pandora FMS>=778<802
Remediation
Information
Fixed in v802 and v800.2
Event History
May 12, 2026
CVE Published
via MITRE·03:13 PM
Data Sourced
via MITRE·03:13 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-34187?
CVE-2026-34187 is classified as a critical severity SQL Injection vulnerability.
2
How do I fix CVE-2026-34187?
To fix CVE-2026-34187, ensure that you update Pandora FMS to version 801 or later.
3
What systems are affected by CVE-2026-34187?
CVE-2026-34187 affects Pandora FMS versions 777 through 800.
4
What type of vulnerability is CVE-2026-34187?
CVE-2026-34187 is an SQL Injection vulnerability caused by improper neutralization of special elements in SQL commands.
5
Can CVE-2026-34187 lead to data compromise?
Yes, CVE-2026-34187 can potentially allow attackers to execute arbitrary SQL code and compromise sensitive data.