---
id: CVE-2026-64947
title: >-
  A chained CSRF bypass and unrestricted file upload vulnerability in the Plugin
  File Manager allows an attacker to upload and execute arbitrary PHP code,
  resulting in Remote Code Execution
summary: >-
  A chained CSRF bypass and unrestricted file upload vulnerability in the Plugin
  File Manager allows an attacker to upload and execute arbitrary PHP code,
  resulting in Remote Code Execution. This issue affects Pandora FMS: from 777
  onwards.
severity: high
cvss: 7.5
cvssVector: >-
  CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/S:N/AU:Y/R:I/V:C/RE:H/U:Red
cwe:
  - CWE-352
  - CWE-434
vendor: Pandora FMS
product: Pandora FMS
affected:
  - pandora_fms 777
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T10:17:15.917'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-64947'
references:
  - url: 'https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/'
    label: security@pandorafms.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-01T09:41:14.164Z'
---

## Overview

A chained CSRF bypass and unrestricted file upload vulnerability in the Plugin File Manager allows an attacker to upload and execute arbitrary PHP code, resulting in Remote Code Execution. This issue affects Pandora FMS: from 777 onwards.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
