CVE-2022-26116: SQL Injection
Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerability [CWE-89] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.2 and below may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-26116?
CVE-2022-26116 is a vulnerability in FortiNAC that allows an authenticated user to perform SQL injection attacks.
Which versions of FortiNAC are affected by CVE-2022-26116?
FortiNAC versions 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.2 and below are affected by CVE-2022-26116.
What is the severity of CVE-2022-26116?
CVE-2022-26116 has a severity rating of 8.8 (high).
How can an authenticated user exploit CVE-2022-26116?
An authenticated user can exploit CVE-2022-26116 by performing SQL injection attacks.
Is there a fix available for CVE-2022-26116?
Yes, Fortinet has released patches and updates to address the CVE-2022-26116 vulnerability. It is recommended to update to a fixed version of FortiNAC.