Database/Control plane, storage & DevOps
Pandora FMS: blind SQL injection through the module parameter of the Grafana datasource endpoint
Impact
The Grafana datasource endpoint concatenates the module parameter into SQL without sanitising it, so any authenticated user can run blind SQL injection against the Pandora FMS database. A monitoring server holds the inventory of the fleet it watches plus the credentials it uses to reach agents and devices, so read access to its database is a map of the environment and often a route to the secrets that come with it. Pandora scores it 7.2 with high confidentiality and low integrity impact. Affects Pandora FMS from version 777 onwards.
Who can reach it
Any account that can authenticate to the Pandora FMS web console and reach the Grafana datasource endpoint over the network. Low privileges are enough; no administrative role is required.
What to do
Upgrade Pandora FMS to the release listed on the vendor's CVE page - the advisory index is the only source given, so confirm the fixed version there rather than assuming one. This is a server-side application update: patch the Pandora console and restart its services. Until then, restrict who can authenticate to the console and block external access to the Grafana datasource endpoint.
References
Related entries
- MongoDB Server: use-after-free in query memory tracking crashes or corrupts the server processCVE-2026-82061 · MongoDB Server (query execution memory tracking)High
- Airflow FAB provider: deactivated accounts keep working through already-issued API tokensCVE-2026-82310 · Apache Airflow FAB provider (Core API token authentication)High
- ATEN Unizon fleet management platform: Unizon is ATEN's centralized manager for its KVM and PDU fleet. The restoreDBCVE-2026-9777 · ATEN Unizon fleet management platformHigh
- CephFS (via OpenStack Manila native driver): A Manila user can request access for an existing CephFS identity and getCVE-2020-27781 · CephFS (via OpenStack Manila native driver)High
- Linux iSCSI: Unprivileged user can craft Netlink messages to scsi_transport_iscsiCVE-2021-27364 · Linux iSCSIHigh
- linuxptp / ptp4l (transparent clock on little-endian): A crafted PTP packet against ptp4l running as a transparentCVE-2021-3571 · linuxptp / ptp4l (transparent clock on little-endian)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.