PatchSiren cyber security CVE debrief
CVE-2026-47685 FOGProject CVE debrief
FOG, a free open-source cloning/imaging/rescue suite/inventory management system, has a vulnerability in versions prior to 1.5.10.1832 and 1.6.0-beta.2313. The unauthenticated inventory service endpoint persists client-supplied values without sanitization. The Host Management Inventory page renders all static inventory fields into HTML without output encoding, allowing stored cross-site scripting that executes in any administrator's browser. This vulnerability has a high CVSS score of 7.3 and is considered a high priority due to the potential for XSS attacks.
- Vendor
- FOGProject
- Product
- Unknown
- CVSS
- HIGH 7.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-22
Who should care
System administrators and users of FOG versions prior to 1.5.10.1832 and 1.6.0-beta.2313 should be aware of this vulnerability and take steps to upgrade to a fixed version. This includes operators managing FOG deployments, platform administrators, vulnerability management teams, and security teams who need to assess and mitigate the risk of stored cross-site scripting (XSS) attacks. Implementing input sanitization and output encoding can help prevent such attacks. Additionally, reviewing compensating controls and monitoring for exposed assets are crucial steps in managing this vulnerability.
Technical summary
The vulnerability exists in the unauthenticated inventory service endpoint (/service/inventory.php) where client-supplied values are persisted without sanitization. This allows an attacker to inject malicious scripts into the inventory data. Furthermore, the Host Management Inventory page renders static inventory fields into HTML without output encoding, enabling stored cross-site scripting (XSS) attacks that can execute in any administrator's browser. The vulnerability has a high CVSS score of 7.3, indicating a high severity level. To mitigate this vulnerability, it is essential to upgrade to versions 1.5.10.1832 or 1.6.0-beta.2313, implement input sanitization for client-supplied values, and ensure output encoding for static inventory fields rendered in HTML.
Defensive priority
High priority due to the high CVSS score of 7.3 and the potential for XSS attacks. System administrators and users of FOG versions prior to 1.5.10.1832 and 1.6.0-beta.2313 should be aware of this vulnerability and take steps to upgrade to a fixed version. Implement input sanitization for client-supplied values and ensure output encoding for static inventory fields rendered in HTML. Track exceptions, retest remediated assets, and close the item only after evidence is documented. Check relevant monitoring, detection, and logs for exposed assets that need extra review. Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Review compensating controls for exposed systems while remediation is scheduled and verified. Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. The CVE record and NVD detail provide information on the vulnerability. The source item URL provides additional context. Affected product deployments may exist in managed environments. Confirm whether FOG versions prior to 1.5.10.1832 and 1.6.0-beta.2313 are in use and assign an owner for follow-up. Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. The unauthenticated inventory service endpoint persists client-supplied values without sanitization, and the Host Management Inventory page renders all static inventory fields into HTML without output encoding. System administrators and users of FOG versions prior to 1.5.10.1832 and 1.6.0-beta.2313 should be aware of this vulnerability and take steps to upgrade to a fixed version. Implement input sanitization for client-supplied values and ensure output encoding for static inventory fields rendered in HTML. Track exceptions, retest remediated assets, and close the item only after evidence is documented. Check relevant monitoring, detection, and logs for exposed assets that need extra review. Plan vendor-supported updates or mitigations through normal change control where exposure is 7.
Recommended defensive actions
- Upgrade to version 1.5.10.1832 or 1.6.0-beta.2313
- Implement input sanitization for client-supplied values
- Ensure output encoding for static inventory fields rendered in HTML
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD detail provide information on the vulnerability. The source item URL provides additional context. Affected product deployments may exist in managed environments. Confirm whether FOG versions prior to 1.5.10.1832 and 1.6.0-beta.2313 are in use and assign an owner for follow-up. Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. The unauthenticated inventory service endpoint persists client-supplied values without sanitization, and the Host Management Inventory page renders all static inventory fields into HTML without output encoding.
Official resources
-
CVE-2026-47685 CVE record
CVE.org
-
CVE-2026-47685 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T21:16:50.543Z and has not been modified since.