PatchSiren

FOGProject CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH FOGProject CVE published 2026-07-21

CVE-2026-47688

CVE-2026-47688 is a high-severity vulnerability in FOG, a free open-source cloning/imaging/rescue suite/inventory management system. An unauthenticated attacker can exploit this vulnerability via a single HTTP GET request to the public 'client' node endpoint, allowing remote wiping of host AES encryption credentials and deletion of all power management scheduled tasks without requiring login, session, or [truncated]

HIGH FOGProject CVE published 2026-07-21

CVE-2026-47687

The FOG Project is vulnerable to a high-severity issue, CVE-2026-47687, which allows an unauthenticated attacker to execute arbitrary JavaScript in an administrator's browser. This issue arises from the `selectForm()` helper in `fogpage.class.php` rendering `<option>` labels using raw, unescaped user input. An attacker who knows any registered host's MAC address can POST a malicious `sysproduct` value to [truncated]