Junglewise Threat Intelligence

CVE-2026-47688: FOG Project missing authorization in clearAES and clearPMTasks

CVE-2026-47688 · Severity: high · CVSS 8.2 · Published 2026-07-21

Executive brief

FOG is an open-source tool used by organizations to manage computer inventory and deploy operating system images to many machines at once. A security flaw allows an unauthenticated attacker to remotely wipe encryption keys and delete scheduled power management tasks (like automatic shutdowns or wake-on-LAN events) for any managed computer. This can disrupt IT operations, break secure communication between the management server and client computers, and potentially expose systems to further attacks during the re-enrollment process.

Technical details

A missing authorization check (CWE-862) in the FOG management interface allows unauthenticated access to the 'client' node endpoint. The 'FOGPageManager::render()' method dynamically invokes sub-methods based on GET parameters without verifying the user's identity or permissions. Specifically, the 'clearAES' and 'clearPMTasks' methods in the 'FOGPage' class are exploitable because they operate on global variables ($id and $groupid) rather than initialized objects. An attacker can send a single HTTP GET request to wipe 'pub_key', 'sec_tok', and 'sec_time' for hosts or destroy power management tasks for groups. This breaks encrypted FOG Client communication and destroys scheduled tasks. The issue is fixed in versions 1.5.10.1832 and 1.6.0-beta.2313.

Affected products

  • FOGProject FOG Project < 1.5.10.1832, < 1.6.0-beta.2313

Timeline

  • 2026-05-19: advisory: GitHub Security Advisory published by FOGProject
  • 2026-07-21: disclosed: CVE published to NVD

References