CVE-2026-64949 — CVSS 8.6 HIGH

Incomplete extension blacklist in the File Manager module allows authenticated upload and execution of arbitrary .phar files. Affects Pandora FMS from 777 onwards.

Loading application…