CVE-2022-26118: Medium severity fortinet fortianalyzer vulnerability
A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a local and authenticated attacker with a restricted shell to escalate their privileges to root due to incorrect permissions of some folders and executable files on the system.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this privilege chaining vulnerability?
The vulnerability ID is CVE-2022-26118.
What software is affected by CVE-2022-26118?
FortiManager and FortiAnalyzer versions 6.0.x, 6.2.x, 6.4.0 through 6.4.7, and 7.0.0 through 7.0.3 are affected.
What is the severity of CVE-2022-26118?
The severity of CVE-2022-26118 is medium, with a CVSS score of 6.7.
How can a local and authenticated attacker exploit CVE-2022-26118?
A local and authenticated attacker with a restricted shell can escalate their privileges to root due to incorrect permissions of some folders and executable.
Is there a fix available for CVE-2022-26118?
Yes, the fix is available from Fortinet. Please refer to the official advisory for more information.