PT-2026-40067 · Unknown · Pandora Fms

CVE-2026-34187

·

Published

2026-05-12

·

Updated

2026-05-14

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pandora FMS versions 777 through 800
Description Improper neutralization of special elements used in an SQL command allows SQL Injection via the graph container parameter. SQL Injection is a technique where an attacker inserts malicious SQL code into a query, potentially allowing them to manipulate the database.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34187

Affected Products

Pandora Fms