CVE-2026-34186: high-severity vulnerability in Pandora FMS
SQL Injection in Custom Fields leads to Database Compromise
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.7epss 0.4%
exploitation probability
0.4%top 64% of all CVEs
observed exploitation
nono source reports it
Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via custom fields. This issue affects Pandora FMS: from 777 through 800
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L/S:N/AU:Y/R:U/V:C/RE:L/U:Amber
Affected products
Pandora FMS · Pandora FMSRelated CVEs — Pandora FMS
In the same product, most dangerous first.
CVE-2024-11320MEDIUMCommand Injection leading to RCE via LDAP MisconfigurationEPSS 91.2%CVE-2024-12971HIGHQuickShell Authenticated Command InjectionEPSS 61.5%CVE-2025-5306HIGHCommand Injection in Netflow pathEPSS 35.7%CVE-2026-34188HIGHOS Command Injection in Event Response ExecutionEPSS 1.7%CVE-2026-30809HIGHOS Command Injection in WebServerModuleDebug via Blacklist Bypass leads to Remote Code ExecutionEPSS 1.6%CVE-2026-30806HIGHOS Command Injection in Network Report leads to Remote Code ExecutionEPSS 1.6%