THREAT OPS › Threat News › [NVD] CVE-2026-47688 (HIGH 8.2) — FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked by an unauthenticated attacker via a single HTTP GET request through the pu
[NVD] CVE-2026-47688 (HIGH 8.2) — FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked by an unauthenticated attacker via a single HTTP GET request through the pu
CVE-2026-47688 CVSS: 8.2 HIGH Published: 2026-07-21T21:16:50.810
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked by an unauthenticated attacker via a single HTTP GET request through the public `client` node endpoint. This allows remote wiping
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-47688cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-47688