cbcvebase.
CVE-2022-26118
published 2022-07-18

CVE-2022-26118: A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a local and…

PriorityP428medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.26%
17.2th percentile
A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a local and authenticated attacker with a restricted shell to escalate their privileges to root due to incorrect permissions of some folders and executable files on the system.

Affected

10 ranges
VendorProductVersion rangeFixed in
fortinetfortianalyzer
fortinetfortianalyzer6.0.0 – 6.0.11
fortinetfortianalyzer6.2.0 – 6.2.9
fortinetfortianalyzer>= 6.4.0 < 6.4.86.4.8
fortinetfortianalyzer>= 7.0.0 < 7.0.47.0.4
fortinetfortimanager
fortinetfortimanager6.0.0 – 6.0.11
fortinetfortimanager6.2.0 – 6.2.9
fortinetfortimanager>= 6.4.0 < 6.4.86.4.8
fortinetfortimanager>= 7.0.0 < 7.0.47.0.4
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.