← back
CVE-2026-64949highCWE-434

Unrestricted File Upload Leading to Remote Code Execution in Admin Tools File Manager

18Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.6
exploitation probability
—
observed exploitation
nono source reports it
Incomplete extension blacklist in the File Manager module allows authenticated upload and execution of arbitrary .phar files. Affects Pandora FMS from 777 onwards.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/S:N/AU:Y/R:I/V:C/RE:M/U:Red