Low severity3.7NVD Advisory· Published Oct 10, 2022· Updated Jun 17, 2026
CVE-2022-26121
CVE-2022-26121
Description
An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11, 5.6.0 through 5.6.11 may allow an unauthenticated and remote attacker to access report template images via referencing the name in the URL path.
Affected products
5cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*range: >5.6.0,<=5.6.11
- (no CPE)range: 7.0.0-7.0.3, 6.4.0-6.4.8, 6.2.0-6.2.9, 6.0.0-6.0.11, 5.6.0-5.6.11
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*range: >5.6.0,<=5.6.11
- (no CPE)range: 7.0.0-7.0.3, 6.4.0-6.4.8, 6.2.0-6.2.9, 6.0.0-6.0.11, 5.6.0-5.6.11
- Fortinet/FortiAnalyzer and FortiManager GUIdescription
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-22-026nvdVendor Advisory
News mentions
0No linked articles in our index yet.