PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47688 FOGProject CVE debrief

CVE-2026-47688 is a high-severity vulnerability in FOG, a free open-source cloning/imaging/rescue suite/inventory management system. An unauthenticated attacker can exploit this vulnerability via a single HTTP GET request to the public 'client' node endpoint, allowing remote wiping of host AES encryption credentials and deletion of all power management scheduled tasks without requiring login, session, or CSRF token. The vulnerability has a CVSS score of 8.2 and is classified as HIGH severity. Affected product deployments should be identified and owners assigned for follow-up.

Vendor
FOGProject
Product
Unknown
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-22
Advisory published
2026-07-21
Advisory updated
2026-07-22

Who should care

Administrators and users of FOG versions prior to 1.5.10.1832 and 1.6.0-beta.2313 should be aware of this vulnerability and take immediate action to update their systems. Affected operators, platforms, and security teams should review vulnerability management and implement compensating controls.

Technical summary

The `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked by an unauthenticated attacker via a single HTTP GET request through the public `client` node endpoint. This allows remote wiping of host AES encryption credentials and deletion of all power management scheduled tasks, with no login, session, or CSRF token required. The vulnerability has a CVSS score of 8.2 and is classified as HIGH severity. Defenders should review official advisories for affected scope and severity.

Defensive priority

High

Recommended defensive actions

  • Update FOG to version 1.5.10.1832 or 1.6.0-beta.2313
  • Restrict access to the public 'client' node endpoint
  • Monitor for suspicious activity
  • Implement additional security measures such as authentication and authorization for sensitive operations
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-07-21T21:16:50.810Z and was last modified on 2026-07-22T14:17:19.767Z. The NVD entry is currently being reviewed. Evidence limits suggest that FOG versions prior to 1.5.10.1832 and 1.6.0-beta.2313 are vulnerable. Defenders should verify affected product deployments and review official advisories for scope and severity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T21:16:50.810Z and has not been modified since then.