CVE-2026-64949: Unrestricted File Upload Leading to Remote Code Execution in Admin Tools File Manager
Incomplete extension blacklist in the File Manager module allows authenticated upload and execution of arbitrary .phar files. Affects Pandora FMS from 777 onwards.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Pandora FMSto a version that resolves this vulnerability.Fixed in v800.5 - Upgrade
Upgrade
Pandora FMSto a version that resolves this vulnerability.Fixed in v805