CVE-2026-30808 - Vulnerability Analysis
HighCVSS: 8.1Last Updated: May 13, 2026
Pandora FMS - Authentication Bypass
Published: May 12, 2026Updated: May 13, 2026Remote Exploitable
Overview
Pandora FMS >= 777 and <= 800 contains a session fixation vulnerability caused by improper session ID handling, letting attackers hijack user sessions via crafted session IDs, exploit requires victim session interaction.
Severity & Score
Severity: High
CVSS Score: 8.1
Impact
Attackers can hijack user sessions, gaining unauthorized access to user accounts and sensitive data.
Mitigation
Update to a version later than 800 or the latest available version.
Related Resources
Details
- CVE ID
- CVE-2026-30808
- Severity
- High
- CVSS Score
- 8.1
- Type
- broken_authentication
- Status
- confirmed
CWE
- CWE-384
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N