PatchSiren cyber security CVE debrief
CVE-2026-47688 FOGProject CVE debrief
CVE-2026-47688 is a high-severity vulnerability in FOG, a free open-source cloning/imaging/rescue suite/inventory management system. An unauthenticated attacker can exploit this vulnerability via a single HTTP GET request to the public 'client' node endpoint, allowing remote wiping of host AES encryption credentials and deletion of all power management scheduled tasks without requiring login, session, or CSRF token. The vulnerability has a CVSS score of 8.2 and is classified as HIGH severity. Affected product deployments should be identified and owners assigned for follow-up.
- Vendor
- FOGProject
- Product
- Unknown
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-22
Who should care
Administrators and users of FOG versions prior to 1.5.10.1832 and 1.6.0-beta.2313 should be aware of this vulnerability and take immediate action to update their systems. Affected operators, platforms, and security teams should review vulnerability management and implement compensating controls.
Technical summary
The `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked by an unauthenticated attacker via a single HTTP GET request through the public `client` node endpoint. This allows remote wiping of host AES encryption credentials and deletion of all power management scheduled tasks, with no login, session, or CSRF token required. The vulnerability has a CVSS score of 8.2 and is classified as HIGH severity. Defenders should review official advisories for affected scope and severity.
Defensive priority
High
Recommended defensive actions
- Update FOG to version 1.5.10.1832 or 1.6.0-beta.2313
- Restrict access to the public 'client' node endpoint
- Monitor for suspicious activity
- Implement additional security measures such as authentication and authorization for sensitive operations
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-07-21T21:16:50.810Z and was last modified on 2026-07-22T14:17:19.767Z. The NVD entry is currently being reviewed. Evidence limits suggest that FOG versions prior to 1.5.10.1832 and 1.6.0-beta.2313 are vulnerable. Defenders should verify affected product deployments and review official advisories for scope and severity.
Official resources
-
CVE-2026-47688 CVE record
CVE.org
-
CVE-2026-47688 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T21:16:50.810Z and has not been modified since then.