Vulnerability Description
A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a local and authenticated attacker with a restricted shell to escalate their privileges to root due to incorrect permissions of some folders and executable files on the system.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortianalyzer | >= 6.0.0, <= 6.0.11 |
| Fortinet | Fortimanager | >= 6.0.0, <= 6.0.11 |
Related Weaknesses (CWE)
References
- https://fortiguard.com/psirt/FG-IR-21-056PatchVendor Advisory
- https://fortiguard.com/psirt/FG-IR-21-056PatchVendor Advisory
FAQ
What is CVE-2022-26118?
CVE-2022-26118 is a vulnerability with a CVSS score of 6.7 (MEDIUM). A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a local and authenticated attacker with a restricted she...
How severe is CVE-2022-26118?
CVE-2022-26118 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-26118?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortianalyzer, Fortinet Fortimanager.