CVE-2026-64948: Missing Authorization in get_module_detail AJAX Endpoint Allows Cross-Group Module Data Disclosure
Published Oct 1, 2026
·Updated
Missing authorization in module data retrieval allows unauthorized cross-group access to module history. Affects Pandora FMS from 777 onwards.
Affected Software
1 affected component
Pandora FMS Pandora FMS>=777
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Pandora FMSto a version that resolves this vulnerability.Fixed in 800.5 - Upgrade
Upgrade
Pandora FMSto a version that resolves this vulnerability.Fixed in 804
Event History
Oct 1, 2026
CVE Published
via MITRE·09:28 AM
Data Sourced
via MITRE·09:28 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Pandora FMS versions from 777 onwards are affected.
2
What level of access does an attacker need?
The CVSS vector indicates that an attacker needs low-level privileges and can exploit the issue remotely without user interaction.
3
What information could be exposed?
An unauthorized user may access module history data belonging to a different group through the get_module_detail AJAX endpoint.