CVE-2026-30805: critical vulnerability in Pandora FMS
Insecure Default Initialization in API Authentication leads to Authentication Bypass
Published
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.1epss 0.5%
exploitation probability
0.5%top 61% of all CVEs
observed exploitation
nono source reports it
Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affects Pandora FMS: from 777 through 800
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/S:N/AU:N/R:U/V:C/RE:M/U:Amber
Affected products
Pandora FMS · Pandora FMSRelated CVEs — Pandora FMS
In the same product, most dangerous first.
CVE-2024-11320MEDIUMCommand Injection leading to RCE via LDAP MisconfigurationEPSS 91.2%CVE-2024-12971HIGHQuickShell Authenticated Command InjectionEPSS 61.5%CVE-2025-5306HIGHCommand Injection in Netflow pathEPSS 35.7%CVE-2026-34188HIGHOS Command Injection in Event Response ExecutionEPSS 1.7%CVE-2026-30809HIGHOS Command Injection in WebServerModuleDebug via Blacklist Bypass leads to Remote Code ExecutionEPSS 1.6%CVE-2026-30806HIGHOS Command Injection in Network Report leads to Remote Code ExecutionEPSS 1.6%