CVE-2026-64946EPSS p4.2%
CVE-2026-64946CVE-2026-64946
Description
A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account takeover. This issue affects Pandora FMS: from 777 onwards.
Scoring
| EPSS | 0.16% probability of exploitation · percentile 4.2% · 2026-10-05T12:00:23Z |
| Last modified | 2026-10-01 |