GPU VulnDB

Database/Control plane, storage & DevOps

Pandora FMS: blind SQL injection through the module parameter of the Grafana datasource endpoint

CVSS 7.2CVE-2026-75786Control plane, storage & DevOpscurated

Impact

The Grafana datasource endpoint concatenates the module parameter into SQL without sanitising it, so any authenticated user can run blind SQL injection against the Pandora FMS database. A monitoring server holds the inventory of the fleet it watches plus the credentials it uses to reach agents and devices, so read access to its database is a map of the environment and often a route to the secrets that come with it. Pandora scores it 7.2 with high confidentiality and low integrity impact. Affects Pandora FMS from version 777 onwards.

Who can reach it

Any account that can authenticate to the Pandora FMS web console and reach the Grafana datasource endpoint over the network. Low privileges are enough; no administrative role is required.

What to do

Upgrade Pandora FMS to the release listed on the vendor's CVE page - the advisory index is the only source given, so confirm the fixed version there rather than assuming one. This is a server-side application update: patch the Pandora console and restart its services. Until then, restrict who can authenticate to the console and block external access to the Grafana datasource endpoint.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.