SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-47688

HIGH · CVSS 8.2 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

FOG's cloning and imaging system is vulnerable to unauthenticated remote access, allowing attackers to execute the `clearAES` and `clearPMTasks` methods via a simple HTTP GET request. This exploit can lead to the remote wiping of AES encryption credentials and deletion of scheduled power management tasks, posing a significant risk to system integrity. Organizations using affected versions should prioritize upgrading to versions 1.5.10.1832 or 1.6.0-beta.2313 to mitigate this high-severity vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-47688
Severity
HIGH
CVSS
8.2
EPSS
0.18%

Original NVD Description

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked by an unauthenticated attacker via a single HTTP GET request through the public `client` node endpoint. This allows remote wiping of host AES encryption credentials and deletion of all power management scheduled tasks, with no login, session, or CSRF token required. Versions 1.5.10.1832 and 1.6.0-beta.2313 fix the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)