What is CVE-2026-47688?
This vulnerability affects the FOG open-source cloning and inventory management system. An unauthenticated attacker can invoke the `clearAES` and `clearPMTasks` methods in `FOGPage` via a simple HTTP GET request through the public `client` node, potentially leading to deletion of critical data. Systems prior to version 1.5.10.1832 are impacted and immediate patching is recommended.
Azərbaycanca: Bu boşluq FOG açıq mənbəli klonlama və inventar idarəetmə sistemində aşkarlanıb. Doğrulamasız hücumçu, ümumi `client` node-u vasitəsilə sadə HTTP GET sorğusu göndərərək `FOGPage`-dəki `clearAES` və `clearPMTasks` metodlarını işə sala bilər ki, bu da kritik məlumatların silinməsinə səbəb ola bilər. Versiya 1.5.10.1832-dən əvvəlki qurğular təsirlənir, dərhal güncəlləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ1
What system does CVE-2026-47688 affect and what can an unauthenticated attacker do?
This vulnerability affects the FOG open-source cloning and inventory management system. An unauthenticated attacker can invoke the `clearAES` and `clearPMTasks` methods in `FOGPage` via a simple HTTP GET request through the public `client` node, potentially leading to deletion of critical data.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.