CVE-2026-64950: Stored Cross-Site Scripting via Directory Name in File Manager Create Directory
Published Oct 1, 2026
·Updated
Missing input validation and output encoding on the directory name parameter in File Manager's Create Directory allows stored XSS, executing without user interaction. Affects Pandora FMS from 777 onwards.
Affected Software
1 affected component
Pandora FMS Pandora FMS>=777
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Pandora FMSto a version that resolves this vulnerability.Fixed in 800.5 - Upgrade
Upgrade
Pandora FMSto a version that resolves this vulnerability.Fixed in 805
Event History
Oct 1, 2026
CVE Published
via MITRE·09:30 AM
Data Sourced
via MITRE·09:30 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Pandora FMS deployments from version 777 onwards are affected.
2
What must an attacker be able to do to exploit this issue?
The attacker needs the ability to submit a directory name through File Manager's Create Directory function. A crafted directory name can be stored and later execute script without user interaction.