vulnerability
Fortinet FortiManager: Exposure of Resource to Wrong Sphere (CVE-2022-26121)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 4 | (AV:N/AC:M/Au:N/C:P/I:N/A:N) | Oct 10, 2022 | Nov 14, 2022 | Aug 1, 2025 |
Severity
4
CVSS
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
Published
Oct 10, 2022
Added
Nov 14, 2022
Modified
Aug 1, 2025
Description
An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11, 5.6.0 through 5.6.11 may allow an unauthenticated and remote attacker to access report template images via referencing the name in the URL path.
Solutions
fortinet-fortimanager-upgrade-5_6_12fortinet-fortimanager-upgrade-6_0_12fortinet-fortimanager-upgrade-6_2_10fortinet-fortimanager-upgrade-6_4_9fortinet-fortimanager-upgrade-7_0_4
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.