PT-2026-40067 · Unknown · Pandora Fms

Published

2026-05-12

·

Updated

2026-05-14

·

CVE-2026-34187

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pandora FMS versions 777 through 800
Description Improper neutralization of special elements used in an SQL command allows SQL Injection via the graph container parameter. SQL Injection is a technique where an attacker inserts malicious SQL code into a query, potentially allowing them to manipulate the database.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-34187

Affected Products

Pandora Fms