---
id: CVE-2026-34190
title: CSRF in Alert Command Deletion
summary: >-
  Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion
  of alert commands via sequential, unvalidated GET requests when an
  authenticated administrator visits a malicious page. This issue affects
  Pandora FMS: from 777…
severity: medium
cvss: 5.9
cvssVector: >-
  CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/S:N/AU:Y/R:U/V:C/RE:L/U:Amber
cvssSource: cna
cwe:
  - CWE-352
vendor: Pandora FMS
product: Pandora FMS
affected:
  - pandora_fms 777
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T09:26:00.782Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-34190'
references:
  - url: 'https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/'
tags:
  - cve.org
ingestedAt: '2026-10-01T09:41:14.167Z'
---

## Overview

Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of alert commands via sequential, unvalidated GET requests when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.

## Affected

- `pandora_fms 777`

## Remediation

Fixed v800.5 and v805
