CVE-2021-26110: High severity fortinet fortiproxy ssl vpn webmode vulnerability
An improper access control vulnerability [CWE-284] in FortiOS autod daemon 7.0.0, 6.4.6 and below, 6.2.9 and below, 6.0.12 and below and FortiProxy 2.0.1 and below, 1.2.9 and below may allow an authenticated low-privileged attacker to escalate their privileges to superadmin via a specific crafted configuration of fabric automation CLI script and auto-script features.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-26110?
CVE-2021-26110 is an improper access control vulnerability in FortiOS autod daemon 7.0.0, 6.4.6 and below, 6.2.9 and below, 6.0.12 and below, and FortiProxy 2.0.1 and below, 1.2.9 and below.
What is the severity of CVE-2021-26110?
The severity of CVE-2021-26110 is high with a CVSS score of 7.8.
How does CVE-2021-26110 impact FortiProxy?
CVE-2021-26110 affects FortiProxy versions 1.0.0 to 1.0.7, 1.1.0 to 1.1.6, 1.2.0 to 1.2.9, 2.0.0, and 2.0.1.
How does CVE-2021-26110 impact FortiOS?
CVE-2021-26110 affects FortiOS versions 5.6.0 to 5.6.14, 6.0.0 to 6.0.12, 6.2.0 to 6.2.9, 6.4.0 to 6.4.6, and 7.0.0.
Is there a reference for CVE-2021-26110?
Yes, you can find more information about CVE-2021-26110 at the following reference: [FortiGuard Advisory FG-IR-20-131](https://fortiguard.com/advisory/FG-IR-20-131).