CVE-2022-26121

LOW

FortiAnalyzer FortiManager GUI <7.0.4 - Info Disclosure

Title source: llm

Description

An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11, 5.6.0 through 5.6.11 may allow an unauthenticated and remote attacker to access report template images via referencing the name in the URL path.

Scores

CVSS v3 3.7
EPSS 0.0018
EPSS Percentile 39.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-668
Status published

Affected Products (2)

fortinet/fortimanager < 5.6.11
fortinet/fortianalyzer < 5.6.11

Timeline

Published Oct 10, 2022
Tracked Since Feb 18, 2026