FG-IR-26-081: Privilege escalation using undocumented CLI command
An Inclusion of Undocumented Features [CWE-1242] in FortiManager and FortiAnalyzer CLI may allow a remote authenticated read-only admin with CLI access to escalate their privilege via use of a hidden command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-26-081?
FG-IR-26-081 is classified as a privilege escalation vulnerability affecting FortiManager and FortiAnalyzer.
How do I fix FG-IR-26-081?
To remediate FG-IR-26-081, update your FortiManager or FortiAnalyzer to the specified versions or later provided in the advisory.
Who is affected by FG-IR-26-081?
FG-IR-26-081 affects remote authenticated read-only administrators with CLI access to FortiManager and FortiAnalyzer devices.
What products are impacted by FG-IR-26-081?
FG-IR-26-081 impacts Fortinet's FortiManager and FortiAnalyzer across multiple versions.
What type of vulnerability is FG-IR-26-081?
FG-IR-26-081 involves the inclusion of undocumented CLI commands leading to privilege escalation.