VYPR
Medium severity6.7NVD Advisory· Published Jul 18, 2022· Updated Jun 17, 2026

CVE-2022-26118

CVE-2022-26118

Description

A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a local and authenticated attacker with a restricted shell to escalate their privileges to root due to incorrect permissions of some folders and executable files on the system.

Affected products

5
  • cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*range: >=6.0.0,<=6.0.11
    • (no CPE)range: 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3
    • (no CPE)range: FortiManager 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3; FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3
  • cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*range: >=6.0.0,<=6.0.11
    • (no CPE)range: 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.