Sceawere

Vulnerability Detail

CVE-2026-16467UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Fortilogger Missing Authorization Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
8h ago
Vendor
Dolusoft Software Technologies
Product
Fortilogger
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Fortilogger: before 6.1.5.9.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-17T13:16:50.963Z",
  "pubdate": "2026-08-17T13:16:50.963Z",
  "executiveSummary": "A Missing Authorization vulnerability has been identified in Dolusoft Software Technologies Fortilogger versions prior to 6.1.5.9. This security flaw stems from an absence of proper access control lists (ACLs) governing specific application functionalities, enabling unauthorized actors to interact with restricted endpoints.\nThe primary impact of this vulnerability is the unauthorized execution of functions that should otherwise be constrained by privilege boundaries, potentially leading to unauthorized data exposure, system manipulation, or administrative function execution depending on the exposed capabilities.\nThe affected product is Dolusoft Software Technologies Fortilogger in versions prior to 6.1.5.9. The risk implications are severe, as exploitation undermines the confidentiality, integrity, and availability guarantees provided by the application's intended authorization architecture.\nAttackers capable of communicating with the vulnerable Fortilogger instance can leverage this flaw to bypass security controls without necessarily possessing the corresponding high-level administrative credentials, assuming network reachability to the vulnerable endpoints.\nAddressing this risk requires immediate application of official vendor patches to remediate the broken access control implementation and restore strict ACL enforcement across all sensitive application routes.",
  "technicalDetails": "The vulnerability is classified under CWE-862 (Missing Authorization), indicating that the software performs an action or grants access to functionality without verifying whether the user has the requisite privileges or permissions to execute the operation safely.\nThe root cause resides within the application routing and request handling logic of Dolusoft Software Technologies Fortilogger before version 6.1.5.9, where certain sensitive functions fail to validate the caller's session tokens, role assignments, or permission mappings against defined ACL policies prior to executing the requested logic.\nThe vulnerable component comprises the backend controllers and request dispatchers responsible for processing administrative or privileged actions within the Fortilogger application architecture. Because these endpoints lack sufficient authorization checks, any entity capable of routing HTTP requests to the target functions can successfully invoke them.\nThe exploitation method involves directly issuing crafted requests, such as HTTP GET or POST methods, to specific, otherwise restricted URLs or API endpoints exposed by the Fortilogger application. The attacker does not need to complete a complex privilege escalation chain if the application logic implicitly trusts the incoming request without contextual session validation.\nThe step-by-step attack flow typically proceeds as follows: First, the attacker maps or identifies the exposed endpoints within the Fortilogger application that handle sensitive operations. Second, the attacker crafts a direct request targeting the unprotected functional endpoint, omitting or providing low-privileged authentication tokens. Third, the backend application processes the request, executing the underlying business logic and returning the result or performing the requested state modification without verifying authorization constraints. Finally, the attacker achieves unauthorized access to restricted application functionality.\nNetwork exposure is inherent to any deployment where the Fortilogger interface is accessible to untrusted networks, although the attack surface may be constrained by network segmentation or perimeter firewalls depending on administrative configurations. Authentication and privilege requirements for exploitation are notably bypassed or degraded due to the flaw, allowing unverified execution of privileged features.\nPost-exploitation impact varies based on the specific functions exposed through the missing authorization flaw, but generally includes unauthorized configuration changes, exposure of sensitive internal system data, or execution of privileged operational routines by unauthorized users."
}
CVE-2026-16467: Fortilogger Missing Authorization Vulnerability (HIGH Severity, CVSS: 7.5) - Sceawere