PT-2026-62110 · Fog · Fog

CVE-2026-47688

·

Published

2026-07-21

·

Updated

2026-08-07

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions FOG versions prior to 1.5.10.1832 FOG versions prior to 1.6.0-beta.2313
Description Unauthenticated attackers can invoke the clearAES() and clearPMTasks() methods within FOGPage by sending a single HTTP GET request to the public client node endpoint. This flaw allows the remote wiping of host AES encryption credentials and the deletion of all scheduled power management tasks without requiring a login, session, or CSRF token.
Recommendations Update to version 1.5.10.1832. Update to version 1.6.0-beta.2313.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47688

Affected Products

Fog