Pandora FMS disclosed two high-severity vulnerabilities affecting versions 777 through 800, including CVE-2026-30804, an unrestricted file upload flaw in the Extension Uploader that can allow remote code execution, and CVE-2026-30811, a missing authorization issue in a configuration AJAX endpoint that can expose sensitive information. The file upload bug is classified as CWE-434, indicating that attackers may be able to upload dangerous file types and execute code on vulnerable systems.
The second flaw, mapped to CWE-276, stems from improper authorization controls and could let unauthorized users access configuration data through the affected endpoint. Both CVE records were published with CVSS v4.0 vectors and vendor references from Pandora FMS, indicating that the issues were formally acknowledged by the vendor and impact the same product range.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On April 13, 2026, CVE entries were published for CVE-2026-30804 and CVE-2026-30811. The records added weakness classifications, CVSS v4.0 vectors, and vendor reference URLs for the affected Pandora FMS issues.
Pandora FMS received a report for CVE-2026-30811 on April 13, 2026. The vulnerability is a missing authorization flaw in a configuration Ajax endpoint that can disclose sensitive information and affects versions 777 through 800.
Pandora FMS received a report for CVE-2026-30804 on April 13, 2026. The flaw is an unrestricted file upload issue in the Extension Uploader that can lead to remote code execution and affects versions 777 through 800.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.