Unauthenticated Remote Code Execution Vulnerability in FOG by FOG Project
CVE-2026-47688
8.2HIGH
What is CVE-2026-47688?
The FOG imaging and cloning software has a vulnerability that exposes two methods, clearAES and clearPMTasks, within the FOGPage component. Unauthenticated attackers can exploit these methods via a straightforward HTTP GET request to the public client node endpoint. This exploitation enables the unauthorized deletion of sensitive AES encryption credentials and the removal of scheduled power management tasks. The issue was rectified in versions 1.5.10.1832 and 1.6.0-beta.2313.
Affected Version(s)
fogproject < 1.5.10.1832 < 1.5.10.1832
fogproject < 1.6.0-beta.2313 < 1.6.0-beta.2313
