CVE-2026-34189: CSRF in Event Response Deletion
Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of event responses via a forged GET request when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Pandora FMSto a version that resolves this vulnerability.Fixed in 805 - Upgrade
Upgrade
Pandora FMSto a version that resolves this vulnerability.Fixed in 800.5
Event History
Frequently Asked Questions
Who is exposed to this issue?
Pandora FMS deployments from version 777 onwards are affected when an administrator is authenticated in the application and can be induced to visit a malicious page.
What does an attacker need to exploit the vulnerability?
The attacker does not need prior authentication, but an authenticated administrator must visit a malicious page. Exploitation uses a forged GET request to trigger deletion of event responses.
What is the impact of successful exploitation?
A successful attack can delete event responses. The provided CVSS vector indicates high impact to integrity and low impact to availability, with no confidentiality impact.