Missing authorization in module data retrieval allows unauthorized cross-group access to module history. Affects Pandora FMS from 777 onwards.
Advisories
No advisories yet.
Fixes
Solution
Fixed v800.5 and v804
Workaround
No workaround given by the vendor.
References
History
Thu, 01 Oct 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pandora Fms
Pandora Fms pandora Fms |
|
| Vendors & Products |
Pandora Fms
Pandora Fms pandora Fms |
Thu, 01 Oct 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing authorization in module data retrieval allows unauthorized cross-group access to module history. Affects Pandora FMS from 777 onwards. | |
| Title | Missing Authorization in get_module_detail AJAX Endpoint Allows Cross-Group Module Data Disclosure | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: PandoraFMS
Published:
Updated: 2026-10-01T09:28:33.626Z
Reserved: 2026-07-21T06:52:17.076Z
Link: CVE-2026-64948
No data.
Status : Deferred
Published: 2026-10-01T10:17:16.057
Modified: 2026-10-01T12:45:05.900
Link: CVE-2026-64948
No data.
OpenCVE Enrichment
Updated: 2026-10-01T14:45:09Z
Weaknesses