CVE-2022-26121: Improper authorization to template image
An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11, 5.6.0 through 5.6.11 may allow an unauthenticated and remote attacker to access report template images via referencing the name in the URL path.
Other sources
An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI may allow an unauthenticatedand remote attacker to access report template images via referencing the name in the URL path.
— FortiGuard
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2022-26121.
What is the severity level of CVE-2022-26121?
The severity level of CVE-2022-26121 is medium with a severity value of 5.3.
Which software products are affected by CVE-2022-26121?
FortiAnalyzer and FortiManager GUI versions 5.6.0 through 5.6.11, 6.0.0 through 6.0.11, 6.2.0 through 6.2.9, 6.4.0 through 6.4.8, and 7.0.0 through 7.0.3 are affected by CVE-2022-26121.
What is the CWE ID of CVE-2022-26121?
The CWE ID of CVE-2022-26121 is CWE-668.
How can an attacker exploit CVE-2022-26121?
An unauthenticated and remote attacker can exploit CVE-2022-26121 to access report template images via a specific URL.