Version: Pandora FMS 800 LTSRelease date: August, 2026
Notices
An error has been detected in some environments during the update process. If the error “ACL forbidden: user does not have permission to execute php update manager” appears, this can be easily resolved by updating to version 800.5 again via WARP offline.

Bug fixes
| FIX LTS # | GitLab # | Description |
|---|---|---|
19984 (24269) |
19838 |
In the Group View, the module count has been corrected to take into account those that are in a critical state and those that are disabled. |
19986 (24276) |
19849 |
The four agent information fields have been amended to allow null values. |
19987 (24272) |
19863 |
In the ‘Monitor Details’ view, the HTTP 500 error that occurred when selecting the fields to display in that list has been fixed. |
19988 (22137) |
19868 |
In PFMS Discovery Task Backup, the process for creating and subsequently editing a weekly task has been fixed. |
20042 |
19973 |
Recursive filtering has been fixed in the Visual Consoles List. |
20043 |
19975
|
Errors relating to the creation of certain rows in the data demonstration feature have been fixed. |
20150 (24303) |
20032 |
In Dashboards, the issue of having two or more ‘List of last events’ widgets in the same container has been fixed. |
20155 (24395) |
20082 |
The display in the Web Console of plugins in the agent view that contain quotation marks in their content has been fixed. |
20169 |
20160 |
Access to the list of Visual Consoles for superadmin users (and those without an assigned profile) has been fixed. |
20174 (24541) |
20171 |
The link in the general search for agents on nodes from the Command Center web console has been fixed. |
20223 |
20219 |
The issue with deleting services has been fixed on both nodes (attached or independent) and in Command Center. |
20224 (24031) |
19503 |
The (offline) access to the Marketplace settings has been fixed. |
20353 (24753, 24699) |
N/A |
En las Operaciones Masivas de Políticas de Monitorización, sección de alertas, fue corregida la visualización de elementos existentes y habilitar así su edición masiva. |
20365 |
20330
|
The display of an event response containing a URL has been corrected in the Events view and its details in the Web Console. |
20366 |
20243 |
The issue with the differentiation of log sources from agents containing EndPoints for MS Windows® has been fixed in the Agent Details view of the Web console. |
20367 |
20284 |
In Network Maps, errors relating to the refresh time of the Web Console and the source group of elements have been fixed. |
20368 |
20292
|
The PFMS update with the “admin” user disabled has been fixed. |
20369 |
20344 |
The redundant button for changing the PFMS Server’s time zone has been removed. |
20371 (24686, 24719) |
20359 |
To ensure that the Warp Update can access the PFMS API correctly, an explicit token has been added for this purpose. This is particularly useful for updating nodes in a Command Center. |
20520 |
19873 |
In the alert templates, in the ‘Condition type’ field, the invalid options have been removed from the list. |
20525 |
16515 |
The access permissions for the script pandora_netflow_wrapper.sh (NetFlow®) have been fixed. |
Improvements and small changes
| Case# | GitLab# | Description |
|---|---|---|
20349 |
20393 |
To improve security, a maximum limit has been set on the number of consecutive failed login attempts; if this limit is reached, the user in question will be permanently blocked. This feature is disabled by default; it applies to superadmin users and operates on standalone nodes and in Command Center (and its nodes). |
20387
|
20257
|
Module graphs have been improved (with and without thresholds, including the representation of module states when unknown) and the PFMS logo has been updated. |
20724 | 20593 |
Support for installation on Ubuntu 24.04 LTS. |
Changes and known limitations
| Case# | GitLab# | Description |
|---|---|---|
19819 |
16085 |
In Command Center, when migrating agents from one node to another, in the specific case where custom fields are present, a warning is displayed regarding incompatibility between fields in the source and destination databases. |
20151 |
20033 |
The ‘Historical database maintenance options’ section has been added to the ‘Performance’ section of the general settings (provided that the historical database is enabled). |
Fixed vulnerabilities
See our Common Vulnerabilities and Exposures (CVE®) list.
| FIX LTS # | GitLab # | Description |
|---|---|---|
|
19983 |
18987 |
The management of Web Push Notifications has been restricted to superadmin users only. Furthermore, the URLs included in notification messages are always those securely configured for the Web Console. |
|
20170 |
20101
|
The privilege escalation from standard users with the “Pandora Administrator” profile to superadmin-type users has been removed. |
|
20440 |
20391 |
The ACLs for the module data displayed via AJAX in the Web Console have been corrected. |
|
20640 |
20596 |
The security of the mechanism for deleting event responses has been improved by changing the method and also by checking for CSRF beforehand. |
|
20641 (20643, 20644, 20645) |
20597, 20599
|
Vulnerabilities relating to arbitrary JavaScript code injection in SVG files have been fixed, along with improvements to file origin authorisation checks, file upload integrity checks, directory creation validation (ensuring filenames contain no special characters), and restrictions on file uploads that could potentially be used to execute arbitrary code. |
|
20642 |
20598 |
The security of the mechanism for copying and deleting alert commands has been fixed by changing the method and also by checking for CSRF beforehand. |








