Loading market data...
← Back to CVE feed

CVE-2026-64946

UNKNOWN View on NVD ↗

Description

A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account takeover. This issue affects Pandora FMS: from 777 onwards.

Published: Oct 01, 2026 10:17 UTC Modified: Oct 01, 2026 15:17 UTC