Unauthenticated Remote Code Execution Vulnerability in FOG by FOG Project
CVE-2026-47688

8.2HIGH

Key Information:

Vendor

Fogproject

Vendor
CVE Published:
21 July 2026

What is CVE-2026-47688?

The FOG imaging and cloning software has a vulnerability that exposes two methods, clearAES and clearPMTasks, within the FOGPage component. Unauthenticated attackers can exploit these methods via a straightforward HTTP GET request to the public client node endpoint. This exploitation enables the unauthorized deletion of sensitive AES encryption credentials and the removal of scheduled power management tasks. The issue was rectified in versions 1.5.10.1832 and 1.6.0-beta.2313.

Affected Version(s)

fogproject < 1.5.10.1832 < 1.5.10.1832

fogproject < 1.6.0-beta.2313 < 1.6.0-beta.2313

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.