CVE-2022-26310
Estado: ModificadaAlta (8.8)—
Pandora FMS v7.0NG.760 and below allows an improper authorization in User Management where any authenticated user with access to the User Management module could create, modify or delete any user with full admin privilege. The impact could lead to a vertical privilege escalation to access the privileges of a higher-level user or typically an admin user.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.69%
- Percentil entre todas las CVEs puntuadas: 51
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-285
- NVD-CWE-Other
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-26310",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@pandorafms.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.3,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 2.1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@pandorafms.com",
"affectedData": [
{
"vendor": "Artica PFMS",
"product": "Pandora FMS",
"versions": [
{
"status": "affected",
"version": "v760",
"versionType": "custom",
"lessThanOrEqual": "v760"
}
],
"platforms": [
"all"
]
}
]
}
],
"published": "2022-08-01T13:15:10.390",
"references": [
{
"url": "https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/",
"tags": [
"Vendor Advisory"
],
"source": "security@pandorafms.com"
},
{
"url": "https://www.incibe.es/en/cve-assignment-publication/coordinated-cves",
"tags": [
"Third Party Advisory"
],
"source": "security@pandorafms.com"
},
{
"url": "https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.incibe.es/en/cve-assignment-publication/coordinated-cves",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@pandorafms.com",
"description": [
{
"lang": "en",
"value": "CWE-285"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Pandora FMS v7.0NG.760 and below allows an improper authorization in User Management where any authenticated user with access to the User Management module could create, modify or delete any user with full admin privilege. The impact could lead to a vertical privilege escalation to access the privileges of a higher-level user or typically an admin user."
},
{
"lang": "es",
"value": "Pandora FMS versión v7.0NG.760 y anteriores, permite una autorización inapropiada en la administración de usuarios donde cualquier usuario autenticado con acceso al módulo de administración de usuarios podría crear, modificar o eliminar cualquier usuario con privilegio de administrador completo. El impacto podría conllevar a una escalada vertical de privilegios para acceder a los privilegios de un usuario de nivel superior o típicamente un usuario administrador"
}
],
"lastModified": "2026-06-17T04:34:57.467",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:pandorafms:pandora_fms:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F9ACE0CF-C204-470A-B706-969837339CDC",
"versionEndIncluding": "7.0_ng_760"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@pandorafms.com"
}